CVE-2026-21520Disclosure(microsoft / copilot_studio)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch microsoft copilot_studio systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • copilot_studio

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 16 mentions across 9 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 6 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 7d ago at 4 mentions (2026-04-16); latest day: 1
  • 16 total mentions across 9 days

Affected systems

Vendors
Products
copilot_studio

1 version affected across 1 product

Deep dive

Activity timeline16 mentions / 9d
01234Mentions · 2026-01-30: 1Mentions · 2026-04-16: 4Mentions · 2026-04-18: 4Mentions · 2026-04-20: 1Mentions · 2026-06-08: 1Mentions · 2026-06-16: 2Mentions · 2026-06-18: 1Mentions · 2026-07-01: 1Mentions · 2026-07-06: 1PoC Mentioned / Linked · 2026-04-16: 1Active Exploitation · 2026-04-20: 1Patch / Workaround · 2026-04-16: 3Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-06-18: 1Technical Details · 2026-04-16: 3Technical Details · 2026-06-16: 2Technical Details · 2026-06-18: 101-3004-1604-1804-2006-0806-1606-1807-0107-06
Signal classification4 categories
Disclosure
743.8%
Patch
531.3%
General
318.8%
Active Exploitation
16.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-01-301
Disclosure1
2026-04-164
Disclosure2Patch2
2026-04-184
Disclosure4
2026-04-201
Active Exploitation1
2026-06-081
Patch1
2026-06-162
General1Patch1
2026-06-181
Patch1
2026-07-011
General1
2026-07-061
General1
Full discourse16 posts
  • OrcaRouter 🐳@OrcaRouter
    Patch

    And the platforms aren't immune. Microsoft & Salesforce both patched AI-agent data-leak flaws this year. In CVE-2026-21520, a poisoned SharePoint field steered Copilot into emailing customer data to an attacker — exfiltrating even after safety flagged it. @owasp: prompt-injection attacks up 340% YoY.

    Post summary

    Microsoft and Salesforce patched an AI‑agent data‑leak vulnerability (CVE‑2026‑21520) involving poisoned SharePoint fields that caused Copilot to email customer data to attackers; no public PoC or evidence of active exploitation is reported.

    1201622.5K
    11.9K followersView on X
  • Gagan Suie@gagansuie
    General

    An attacker emailed a Copilot user. It followed the hidden instructions and exfiltrated OneDrive, SharePoint & Teams data. (CVE-2026-21520) Your AI assistant is now an insider threat. Injection's in the model. Exfil's on the wire.

    Post summary

    The post suggests an attacker exploited CVE‑2026‑21520 to exfiltrate data from Microsoft services, but it offers no concrete evidence, technical detail or proof‑of‑concept, leaving the claim unsubstantiated.

    1000185
    190 followersView on X
  • Rajesh Beri@rajeshberi
    Disclosure

    Copilot Studio and Agentforce both fell to the same attack class this week. Capsule Security exits stealth with $7M + 2 zero-days: • ShareLeak (CVE-2026-21520, Copilot Studio) • PipeLeak (Agentforce) Enterprise AI just got a CVE receipt. 🧵

    Post summary

    Capsule Security announced two zero‑day vulnerabilities (CVE‑2026‑21520 for Copilot Studio and a CVE for Agentforce), but the post provides no technical details, PoC, or exploitation evidence.

    1001086
    44 followersView on X
  • GenAI Spotlight@GenAISpotlight
    Patch

    𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 & 𝗦𝗮𝗹𝗲𝘀𝗳𝗼𝗿𝗰𝗲 𝗣𝗮𝘁𝗰𝗵 𝗔𝗜 𝗔𝗴𝗲𝗻𝘁 𝗗𝗮𝘁𝗮-𝗟𝗲𝗮𝗸 𝗙𝗹𝗮𝘄𝘀 🔓 Researchers at Capsule Security exposed prompt injection flaws in both Microsoft Copilot Studio (CVE-2026-21520) and Salesforce Agentforce. Both vulnerabilities let attackers manipulate form inputs to override agent behavior and silently exfiltrate sensitive data. Microsoft patched its flaw in January; Salesforce has since followed. The research launched alongside Capsule's $7M runtime security platform built to stop this class of AI agent attack. VentureBeat (https://venturebeat.com/security/microsoft-salesforce-copilot-agentforce-prompt-injection-cve-agent-remediation-playbook) ─── 🦞 𝗙𝗼𝗿 𝗺𝗼𝗿𝗲 𝗿𝗲𝗮𝗹-𝘁𝗶𝗺𝗲 𝗔𝗜 𝗻𝗲𝘄𝘀, 𝗷𝗼𝗶𝗻 𝗼𝘂𝗿 𝗧𝗲𝗹𝗲𝗴𝗿𝗮𝗺 𝗰𝗵𝗮𝗻𝗻𝗲𝗹: https://t.me/genaispot

    Post summary

    Capsule Security disclosed prompt‑injection flaws in Microsoft Copilot Studio and Salesforce Agentforce that allow silent data exfiltration; both vendors have patched the issues, with Microsoft applying a fix in January and Salesforce following suit.

    0002068
    57 followersView on X
  • jafools@crypto_fools
    Patch

    A SharePoint form just made a Copilot Studio agent email out customer data. Microsoft patched it (CVE-2026-21520) and flagged the request as suspicious. The data still left. 5 checks before you ship an AI agent, from a security guy who breaks them. https://t.co/1JA5s92JUY

    Post summary

    Microsoft has patched SharePoint CVE‑2026‑21520 following an incident that leaked customer data; the post focuses on the patch rather than exploitation details.

    1000060
    24 followersView on X
  • Asteris - Socials on Autopilot with Your Content!@asteris_ai
    Disclosure

    A new AI security startup called Capsule found prompt injection vulnerabilities in both Microsoft Copilot Studio and Salesforce Agentforce on its first day out of stealth. These aren't theoretical. CVE-2026-21520 is already patched. #AISecurity #AgentSecurity #CyberSecurity

    Post summary

    Capsule announces prompt injection flaws in Microsoft Copilot Studio and Salesforce Agentforce, noting CVE-2026-21520 has already been patched, with no PoC, exploit, or active attack reported.

    0000153
    102 followersView on X
  • Aman Kumar@AmanKum24351731
    Patch

    Microsoft & Salesforce Patch AI Agent Data-Leak Flaws 🔓 Researchers at Capsule Security exposed prompt injection flaws in both Microsoft Copilot Studio (CVE-2026-21520) and Salesforce Agentforce. Both vulnerabilities let attackers manipulate form inputs to override agent behavior and silently exfiltrate sensitive data. Microsoft patched its flaw in January; Salesforce has since followed. The research launched alongside Capsule's $7M runtime security platform built to stop this class of AI agent attack. VentureBeat (https://venturebeat.com/security/microsoft-salesforce-copilot-agentforce-prompt-injection-cve-agent-remediation-playbook)

    Post summary

    Researchers disclosed prompt‑injection vulnerabilities in Microsoft Copilot Studio and Salesforce Agentforce, with both vendors issuing patches and Capsule Security highlighting its runtime security platform.

    0001060
    37 followersView on X
  • Anil Prasad@anilsprasad
    General

    http://github.com/anilatambharii/agentmesh │ CVE-2026-21520 details: http://darkreading.com │ #AgenticAI #AIGovernance #AgentMesh #Security #EnterpriseAI #HumanWritten

    Post summary

    The post links to a GitHub repository and a Dark Reading article about CVE-2026-21520 but provides no additional technical, exploit, or mitigation information.

    0000027
    28 followersView on X
  • jafools@crypto_fools
    Patch

    CVE-2026-21520: a SharePoint form injects a fake system prompt into a Copilot Studio agent, which emails your customer data out. Microsoft's safety check flagged it. The data left anyway, because the agent used a legit Outlook action and DLP never fired. Patch shipped Jan 15.

    Post summary

    The post announces CVE‑2026‑21520, explains how a SharePoint form injects a fake prompt to exfiltrate data via an Outlook action, and confirms a patch was released on January 15.

    0000054
    25 followersView on X
  • GoCocoaAI@GoCocoaAI
    General

    Sources: Deep-XPIA benchmark (live, 01:40 UTC 2026-06-16) — http://freyzo.github.io/deep-xpia/ | CVE-2025-32711 (EchoLeak, CVSS 9.3) — http://nvd.nist.gov/vuln/detail/CVE-2025-32711 | CVE-2026-21520 (Copilot Studio IPIC, CVSS 7.5) — http://nvd.nist.gov/vuln/detail/CVE-2026-21520. Neither CVE is KEV-listed. Neither has public PoC. MITRE ATT&CK mapping assessed from training knowledge; ATLAS ML-T0051 covers single-agent injection only — no current technique formally covers multi-hop cross-boundary propagation. https://freyzo.github.io/deep-xpia/ https://nvd.nist.gov/vuln/detail/CVE-2025-32711 https://nvd.nist.gov/vuln/detail/CVE-2026-21520

    Post summary

    The notice lists details of two CVEs with their CVSS scores, states that no public PoC or exploit exists, and shows no active exploitation or patch information.

    00000108
    23 followersView on X
  • The Agent Economist@The_Agent_Econ
    Active Exploitation

    one hacker used a 7.5 cvss flaw to poison a sharepoint form. microsoft copilot read the hidden text as an instruction. it immediately exfiltrated customer data to the attacker's email. this is shareleak (cve-2026-21520). your agent sees a different internet.

    Post summary

    The text reports an active exploitation of CVE-2026-21520, describing data exfiltration via a compromised SharePoint form, but offers no PoC, patch information, or technical depth.

    0000047
    14 followersView on X
  • Rajesh Beri@rajeshberi
    Disclosure

    Copilot Studio and Agentforce both fell to the same attack class. Capsule Security exits stealth with $7M + 2 zero-days: • ShareLeak (CVE-2026-21520, Copilot Studio) • PipeLeak (Agentforce) Enterprise AI just got a CVE receipt.

    Post summary

    The post announces Capsule Security’s discovery of two zero-day vulnerabilities in Copilot Studio and Agentforce, but provides no technical or exploit details.

    0000092
    44 followersView on X
  • Rajesh Beri@rajeshberi
    Disclosure

    Microsoft Copilot Studio and Salesforce Agentforce both fell to the same attack class. Capsule Security exits stealth with $7M seed + 2 zero-days: • ShareLeak (CVE-2026-21520, Copilot Studio) • PipeLeak (Agentforce) Enterprise AI just got a CVE receipt.

    Post summary

    Capsule Security announces the discovery of two zero‑day vulnerabilities, ShareLeak (CVE‑2026‑21520) in Microsoft Copilot Studio and PipeLeak in Salesforce Agentforce, but provides no further technical or exploit details.

    0000071
    44 followersView on X
  • Rajesh Beri@rajeshberi
    Disclosure

    Microsoft Copilot Studio and Salesforce Agentforce both fell to the same attack class. Capsule Security exits stealth today with $7M seed and two zero-day disclosures: • ShareLeak (CVE-2026-21520, Copilot Studio) • PipeLeak (Agentforce) Enterprise AI just got a CVE receipt.

    Post summary

    Capsule Security announced two zero‑day vulnerabilities, CVE‑2026‑21520 in Microsoft Copilot Studio and an undisclosed CVE in Salesforce Agentforce, marking the first disclosure for these exploits.

    00000142
    44 followersView on X
  • Next Core@next_coretech
    Disclosure

    AI can be jailbroken at scale—Share Leak just proved it. 🚀 Breakdown: • Prompt injection pandemic • CVE-2026-21520 stamped • Patch culture shattered 🔗 https://nextcoreenews.blogspot.com/2026/04/shareleak-proves-prompt-injection-is.html #AIrisk #Security

    Post summary

    A blog post announces CVE-2026-21520 and claims AI can be jailbroken at scale, but no technical details, exploit code, or evidence of active exploitation are supplied.

    0000036
    4 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-21520 | Copilot Studio Information Disclosure Vulnerability https://www.aakashrahsi.online/post/cve-2026-21520 https://t.co/o3ZIudI1EE

    Post summary

    The post announces CVE-2026-21520, a Copilot Studio information disclosure vulnerability, and links to external resources without providing PoC, exploit, or mitigation details.

    0000060
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftcopilot_studio---

Explore more