logo

Microsoft 365 Copilot Flaws Could Let Attackers Access Sensitive Data

ID: ef91bdca-669d-517a-9b88-3251fb85ba1c

STIX ID: report--ef91bdca-669d-517a-9b88-3251fb85ba1c

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Divya

...
...

Microsoft disclosed three information-disclosure vulnerabilities in Microsoft 365 Copilot and Copilot Chat in Edge (CVE-2026-26129, CVE-2026-26164, CVE-2026-33111) that could allow attackers to exfiltrate sensitive enterprise data via prompt-injection and command-injection techniques; all three are rated CVSS 3.1 base score 7.5 and affect confidentiality. Microsoft states it has deployed backend fixes for the managed Copilot service and that no customer action is required, so tenants are automatically protected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.