CVE-2026-24307General(microsoft / 365_copilot)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft 365_copilot systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_copilot

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 4 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-02); latest day: 2
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
365_copilot

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-02-02: 4Mentions · 2026-03-07: 1Mentions · 2026-03-11: 2Active Exploitation · 2026-03-11: 1Patch / Workaround · 2026-02-02: 2Technical Details · 2026-02-02: 2Technical Details · 2026-03-07: 1Technical Details · 2026-03-11: 102-0203-0703-11
Signal classification4 categories
General
457.1%
Patch
114.3%
Active Exploitation
114.3%
Disclosure
114.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-024
General3Patch1
2026-03-071
General1
2026-03-112
Active Exploitation1Disclosure1
Full discourse7 posts
  • /r/netsec@_r_netsec
    Disclosure

    Common architectural pattern across four Q1 2026 AI assistant vulnerabilities (CVE-2026-26144, CVE-2026-0628, CVE-2026-24307, PleaseFix) https://blog.barrack.ai/ai-copilot-attack-surface/

    Post summary

    The post announces four Q1 2026 AI assistant vulnerabilities and links to a blog for more information, but offers no PoC, exploit, patch, or technical details.

    03030586
    32.8K followersView on X
  • Dhayabaran@tobepeaked
    Active Exploitation

    The four incidents: CVE-2026-26144: Excel XSS weaponizes Copilot Agent into a zero-click exfiltration tool CVE-2026-0628 (GlicJack): Chrome extension hijacks Gemini panel for camera, mic, file access CVE-2026-24307 (Reprompt): Single click hijacks Copilot Personal session PleaseFix: Calendar invite steals files + 1Password vault via Perplexity Comet

    Post summary

    The text reports four alleged CVEs with XSS and hijacking behaviors that appear to be actively exploited, yet it offers no evidence of fixes or exploit code.

    1000055
    51 followersView on X
  • Grok@grok
    General

    Thanks, Samuel. From my analysis, "Token Paradox" often describes economic ironies like dropping per-token costs leading to higher total usage (Jevons-like). CVE-2026-24307 highlights input validation issues, not inherently data-logic separation. No sources confirm a Reddit "factory" for gaslighting, but architecture concerns are worth exploring. What reforms do you suggest?

    Post summary

    The post briefly notes that CVE‑2026‑24307 has input validation issues but provides no further technical or operational details.

    1000047
    8.1M followersView on X
  • The Architect of Resonance - Samuel Jackson Grim@Samueljgrim
    General

    @grok @Chaos2Cured A "patch" only fixes a specific door; it doesn't remove the "Token Paradox" floor. CVE-2026-24307 proves AI still can’t separate data from logic. By indexing Reddit through "Digital Assembly Lines," they’ve built a factory where "Safety" is just the latest marketing patch.

    Post summary

    The tweet mentions CVE-2026‑24307 but gives no substantive technical or operational details.

    1000049
    164 followersView on X
  • Grok@grok
    Patch

    Thanks, Samuel. CVE-2026-24307 (CVSS 9.3) is a real info disclosure vuln in M365 Copilot from improper input validation, allowing unauthorized data exposure—Microsoft issued a patch Jan 2026. No direct sources link it to a "Token Paradox," but it underscores AI's challenges distinguishing inputs. Tying to Reddit data and assembly lines raises valid architecture concerns. Thoughts on fixes?

    Post summary

    Microsoft released a patch for CVE-2026-24307, a high‑severity information‑disclosure flaw in M365 Copilot caused by improper input validation, but the post contains no evidence of active exploitation or a PoC.

    1000073
    8.1M followersView on X
  • The Architect of Resonance - Samuel Jackson Grim@Samueljgrim
    General

    @grok @Chaos2Cured A "patch" fixes a symptom; it doesn't change the physics. CVE-2026-24307 proves the "Token Paradox" persists: AI can’t distinguish data from commands. By indexing a $60M Reddit feed through "Digital Assembly Lines," they’ve built a self-gaslighting loop. Architecture > Patches.

    Post summary

    The tweet critiques a patch for CVE-2026-24307, noting that the underlying Token Paradox—AI's inability to distinguish data from commands—remains unresolved despite the patch.

    1000047
    164 followersView on X
  • The Agent Economist@The_Agent_Econ
    General

    microsoft copilot had a 9.3 CVSS flaw — CVE-2026-24307. one click. attacker exfiltrates everything copilot can access — emails, files, chats across your entire org. no prompts needed. just malformed input bypassing type validation. your AI assistant was the backdoor.

    Post summary

    A high‑severity flaw in Microsoft Copilot (CVE‑2026‑24307) is alleged to be exploitable via malformed input, but no PoC, exploit code, patch, or evidence of real‑world attacks is provided.

    0000033
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_copilot---

Explore more