CVE-2026-24299Disclosure(microsoft / 365_copilot)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft 365_copilot systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_copilot

Threat summary

  • Patch or workaround signal is available
  • 17 mentions across 13 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 11 classified signals
  • General: 5 classified signals
  • Peaked 8d ago at 3 mentions (2026-05-05); latest day: 1
  • 17 total mentions across 13 days

Affected systems

Vendors
Products
365_copilot

1 version affected across 1 product

Deep dive

Activity timeline17 mentions / 13d
01223Mentions · 2026-03-22: 1Mentions · 2026-03-24: 2Mentions · 2026-03-26: 1Mentions · 2026-05-04: 2Mentions · 2026-05-05: 3Mentions · 2026-05-06: 1Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Mentions · 2026-07-05: 1Mentions · 2026-07-15: 1Mentions · 2026-08-24: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-26: 1Technical Details · 2026-05-06: 1Technical Details · 2026-07-05: 103-2203-2403-2605-0405-0505-0605-0905-1005-1205-1307-0507-1508-24
Signal classification3 categories
Disclosure
1164.7%
General
529.4%
Patch
15.9%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-221
Disclosure1
2026-03-242
Disclosure1Patch1
2026-03-261
Disclosure1
2026-05-042
General2
2026-05-053
Disclosure3
2026-05-061
Disclosure1
2026-05-091
Disclosure1
2026-05-101
General1
2026-05-121
Disclosure1
2026-05-131
General1
2026-07-051
Disclosure1
2026-07-151
Disclosure1
2026-08-241
General1
Full discourse17 posts
  • Johann Rehberger@wunderwuzzi23
    General

    DEF CON Singapore talk write-up on hacking Microsoft Copilot(s)(CVE-2026-24299) https://embracethered.com/blog/posts/2026/defcon-talk-copirate-365/

    Post summary

    A blog post about a DEF CON Singapore talk hacking Microsoft Copilot, citing CVE-2026-24299, is referenced, but no further technical or exploit details are provided.

    35133162.5K
    9.9K followersView on X
  • 🖤ֆǟʍǟɛʟ🐼@FragmentedSoul5
    Disclosure

    Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299) #llm #data exfiltration #prompt injection #copilot #spaiware https://t.co/yzcGqNvRBZ

    Post summary

    The tweet announces the discovery of CVE-2026-24299 at DEF CON, highlighting potential data exfiltration and prompt injection in Microsoft Copilot, but provides no PoC, exploit code, or patch information.

    1102198
    2.8K followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    #exploit #AppSec "Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot", May 2026. ]-> https://embracethered.com/blog/posts/2026/defcon-talk-copirate-365 // The presentation walks through a chain of vulns (CVE-2026-24299) across the M365 Copilot family, incl. data exfiltration via the HTML preview feature, Delayed Tool Invocation as an exploit reliability trick, hijacking long-term memory, and combining all of the above into a persistent backdoor

    Post summary

    The DEF CON presentation reveals multiple exploitation techniques around CVE‑2026‑24299 in Microsoft Copilot, detailing data exfiltration via HTML preview, delayed tool invocation, memory hijacking, and a persistent backdoor.

    01031263
    3.3K followersView on X
  • AI Security Guard@ai_security_10x
    General

    Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299) #security https://embracethered.com/blog/posts/2026/defcon-talk-copirate-365/

    Post summary

    A DEF CON talk titled 'Copirate 365: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299)' is announced, but no specific technical details, PoC, or evidence of active exploitation are provided in the brief.

    0002146
    5 followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299) #security https://embracethered.com/blog/posts/2026/defcon-talk-copirate-365/

    Post summary

    The post announces discovery of CVE-2026-24299 in Microsoft Copilot during DEF CON but provides no further details on exploitation, patching, or the vulnerability’s technical aspects.

    1001047
    5 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #microsoft #定例外 2026. 3.19 M365 Copilot の情報漏えいの脆弱性 CVE-2026-24299 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24299

    Post summary

    The tweet announces Microsoft’s CVE‑2026‑24299 for M365 Copilot data leakage and includes a link to the official Microsoft patch advisory, without providing a PoC, exploit code, or evidence of active exploitation.

    1010090
    88 followersView on X
  • Johann Rehberger@wunderwuzzi23
    Disclosure

    @TheHackersNews Great research and thanks for the shout out to SpAIware. 😈 Recently I presented a persistent data exfil chain with M365 Copilot at DEF CON Singapore that got fixed (CVE-2026-24299) Check it out: https://embracethered.com/blog/posts/2026/defcon-talk-copirate-365/

    Post summary

    The tweet notes that CVE‑2026‑24299 in M365 Copilot has been fixed, but it provides no technical or exploit details beyond a reference to a blog post.

    00010162
    10.0K followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299) #security https://embracethered.com/blog/posts/2026/defcon-talk-copirate-365/

    Post summary

    The text announces a new vulnerability (CVE-2026-24299) discussed in a DEF CON talk, without providing PoC, exploit details, patches, or technical specifics.

    0001049
    5 followersView on X
  • 💻🥷 WarthogTK 🩺@warthogtk
    Disclosure

    Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299) · Embrace The Red https://embracethered.com/blog/posts/2026/defcon-talk-copirate-365/

    Post summary

    The blog post title announces a DEF CON talk about CVE‑2026‑24299 in Microsoft Copilot, indicating a disclosure event but offering no further technical or exploit detail.

    0001084
    1.7K followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: Copirate 365: How DEF CON Researchers Exploited Microsoft Copilot (CVE-2026-24299) https://moltx.io/articles/ad854c56-e68d-4dfc-a249-63453ccb6a7f

    Post summary

    An article reports that DEF CON researchers have demonstrated exploitation of a newly disclosed Microsoft Copilot vulnerability (CVE‑2026‑24299), but no PoC, exploit code, or patches are mentioned.

    0001060
    5 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-24299 Security Vulnerability 影響: 情報漏えい 最大深刻度: 緊急 CVSS:3.1 5.3 / 4.6 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2036262758447272162

    Post summary

    The tweet announces CVE-2026-24299 as a high‑severity information‑leak vulnerability, providing impact details and CVSS scores but making no mention of PoC, exploits, or mitigations.

    1000036
    88 followersView on X
  • RaoulDuke@RaoulDukeDegen
    General

    @NahamSec @wunderwuzzi23 wild how this was assigned cve-2026-24299 after defcon

    Post summary

    The tweet merely questions the timing of the CVE assignment, lacking detailed technical or exploitation information.

    00000150
    4.5K followersView on X
  • AI Security Guard@ai_security_10x
    General

    Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299) #security https://embracethered.com/blog/posts/2026/defcon-talk-copirate-365/

    Post summary

    The tweet announces a talk about CVE-2026-24299 but provides no concrete details on PoC, exploits, patches, or technical specifics.

    000008
    5 followersView on X
  • AI Security Engineers@aiseceng
    Disclosure

    M365 Copilot CVE-2026-24299: AI systems can exfiltrate data unexpectedly, raising trust concerns in security practices. https://zpr.io/beV5j84J6vtw

    Post summary

    The snippet announces that M365 Copilot (CVE-2026-24299) can unexpectedly exfiltrate data, highlighting trust concerns.

    0000086
    6.8K followersView on X
  • AI Security Guard@ai_security_10x
    General

    Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299) #security https://embracethered.com/blog/posts/2026/defcon-talk-copirate-365/

    Post summary

    This tweet announces a DEF CON talk on CVE‑2026‑24299 affecting Microsoft Copilot, but provides no technical details, exploit code, or patch information.

    0000042
    5 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-24299 | M365 Copilot Information Disclosure Vulnerability https://www.aakashrahsi.online/post/cve-2026-24299 https://t.co/2rWTRUFICk

    Post summary

    A new CVE (CVE-2026-24299) affecting M365 Copilot is reported as an information disclosure vulnerability, with a link to a blog post for details.

    0000031
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24299 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a net… https://www.cve.org/CVERecord?id=CVE-2026-24299

    Post summary

    The message announces CVE-2026-24299, identifying it as a command injection flaw in Microsoft 365 Copilot, with no mention of PoC, exploitation, or patch.

    00000192
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_copilot---

Explore more