logo

Critical SearchLeak Vulnerability in Microsoft 365 Copilot Allows One-Click Data Theft

ID: 517aaf84-0a7b-54f5-8ab5-3c4b553a6a72

STIX ID: report--517aaf84-0a7b-54f5-8ab5-3c4b553a6a72

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-15

Date Updated: 2026-06-16

...
...

A critical vulnerability chain named SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot Enterprise allowed attackers to exfiltrate sensitive data (emails, calendars, OneDrive/SharePoint files) with a single click by chaining a 'q' parameter prompt injection, an HTML rendering race condition, and an SSRF through Bing; Microsoft patched the issue on June 4, 2026, and no evidence of in-the-wild exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.