Critical SearchLeak Vulnerability in Microsoft 365 Copilot Allows One-Click Data Theft
ID: 517aaf84-0a7b-54f5-8ab5-3c4b553a6a72
STIX ID: report--517aaf84-0a7b-54f5-8ab5-3c4b553a6a72
Feed Name: ThreatCluster
Threat Score
A critical vulnerability chain named SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot Enterprise allowed attackers to exfiltrate sensitive data (emails, calendars, OneDrive/SharePoint files) with a single click by chaining a 'q' parameter prompt injection, an HTML rendering race condition, and an SSRF through Bing; Microsoft patched the issue on June 4, 2026, and no evidence of in-the-wild exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
