CVE-2026-26129Disclosure(microsoft / 365_copilot_chat)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft 365_copilot_chat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-138

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_copilot_chat

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 11 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 5d ago at 4 mentions (2026-05-08); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
365_copilot_chat

1 version affected across 1 product

Deep dive

Activity timeline13 mentions / 7d
01234Mentions · 2026-05-07: 1Mentions · 2026-05-08: 4Mentions · 2026-05-09: 2Mentions · 2026-05-10: 3Mentions · 2026-05-13: 1Mentions · 2026-05-15: 1Mentions · 2026-05-19: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-09: 2Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-08: 4Technical Details · 2026-05-09: 2Technical Details · 2026-05-10: 3Technical Details · 2026-05-15: 1Technical Details · 2026-05-19: 105-0705-0805-0905-1005-1305-1505-19
Signal classification4 categories
Disclosure
538.5%
Patch
430.8%
General
323.1%
Discloruy
17.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-071
Patch1
2026-05-084
Disclosure1General2Patch1
2026-05-092
Disclosure1Patch1
2026-05-103
Disclosure2Patch1
2026-05-131
General1
2026-05-151
Discloruy1
2026-05-191
Disclosure1
Full discourse13 posts
  • International Cyber Digest@IntCyberDigest
    Patch

    ‼️🚨 Microsoft just patched three critical M365 Copilot data leak vulnerabilities. All three are network-reachable, unauthenticated, and zero-click. M365 Copilot Business Chat usually has access to a tenant's SharePoint, OneDrive, Outlook, Teams, and more. ▪️ CVE-2026-26129 (M365 Copilot Business Chat): improper neutralization of special elements. Information disclosure. ▪️ CVE-2026-26164 (M365 Copilot Business Chat): output injection into a downstream component. Information disclosure. ▪️ CVE-2026-33111 (Copilot Chat in Microsoft Edge): command injection. Information disclosure. Copilot was server-side patched, so no customer action is required. Microsoft has published no technical details and there is no PoC.

    Post summary

    Microsoft patched three critical Microsoft 365 Copilot vulnerabilities with no customer action required, and no proof-of-concept or active exploitation was reported.

    1188438614537.7K
    184.6K followersView on X
  • Kruptos@KuptoKosmos
    Disclosure

    🚨💻🗃️ MICROSOFT COPILOT... LES DONNÉES D’ENTREPRISE ÉTAIENT OPEN BAR AVEC 3 FAILLES ZERO-CLICK !! 🤫 Le 7 mai 2026, Microsoft a silencieusement patché 3 vulnérabilités critiques dans M365 Copilot (Business Chat) et Copilot Chat dans Edge Les CVE : 2026-26129, 2026-26164 et 2026-33111 Zero-click. Zéro interaction... 🤨 Un attaquant distant, même pas authentifié, pouvait littéralement se servir comme à l’open bar dans tes données d’entreprise ! Pendant ce temps, Copilot continuait tranquillement à fouiller dans ton Graph : mails Outlook, docs SharePoint/OneDrive, Teams, calendriers, contrats, données RH, secrets commerciaux… Tout y passait ➡️ Ces 3 failles sont du même moule : injection dans la sortie (output injection/command injection) Clairement... Copilot crachait du contenu mal filtré, et un composant en aval (interne Microsoft) le prenait au mot et balançait des données sensibles qu’il n’aurait JAMAIS dû exposer !! 👉 CVE-2026-26129 & 26164 (Business Chat) 👉 CVE-2026-33111 (Copilot dans Edge) Score CVSS 7.5, mais dans la vraie vie c'est critique absolue parce que c’est réseau, zéro auth, et que Copilot a accès à tout ce qui fait le nerf de la guerre en entreprise ! ⚠️ Tu n’as rien à faire. Tu bosses normalement, Copilot interroge le Graph pour "t’aider"... et bam, une requête craftée depuis l’extérieur suffit Pas besoin d’infecter un poste, pas besoin d’un mail piégé. Juste une IA trop puissante avec des filtres de sortie faits au lance-pierre ! 🤦‍♂️ Résultat n’importe quelle boîte qui avait déployé Copilot devenait une piñata de données ouverte 24/7 Microsoft a tout corrigé côté serveur (patch automatique, rien à faire pour les admins). Pas de PoC public, pas de détails techniques (on connaît la chanson) Mais c'était clairement open bar total !!! C’est encore une fois le grand classique Microsoft : on donne un super-pouvoir à une IA qui voit absolument tout et on oublie de sécuriser les sorties Comme la mémoire dump d’Edge l’autre jour 🙄 En 2026, on confie nos données les plus sensibles à des boîtes qui considèrent que "c’est normal que ça fuite un peu" !! Si t’es en entreprise et que vous roulez sur Copilot Business vérifie que le patch est bien propagé Et sinon… tu sais ce qu’il te reste à faire : logs en mode parano et œil sur tes données ! Bref... on continue de payer cher pour des "outils intelligents" qui nous rendent surtout plus vulnérables. #CyberSecurity #Microsoft 🤡

    Post summary

    Microsoft disclosed three critical zero‑click vulnerabilities in its Copilot services, identified by CVEs 2026‑26129, 2026‑26164, and 2026‑33111, detailing their injection nature and CVSS score, and announced automatic server‑side patches without reporting active exploitation or a PoC.

    625450162.9K
    8.6K followersView on X
  • iototsecnews@iototsecnews
    Discloruy

    Microsoft 365 Copilot の脆弱性 CVE-2026-26129/26164/33111 が FIX:情報漏洩の恐れ https://iototsecnews.jp/2026/05/09/critical-microsoft-365-copilot-vulnerabilities-expose-sensitive-information/ Microsoft の AI ツール Copilot に見つかった、情報漏洩の脆弱性について解説する記事です。問題の原因は、 AI が出力したコマンドを実行する際などに、特殊要素に対する適切な無害化 (サニタイズ) が行われなかったことにあります。 具体的には、Copilot の CVE-2026-26129/ CVE-2026-26164 と、 Edge の CVE-2026-33111 といった脆弱性により、 リモートの攻撃者が組織の機密情報を盗み出せるリスクが生じていました。ご利用のチームは、ご注意ください。 #CVE202626129 #CVE202626164 #CVE202633111 #Microsoft365Copilot #Vulnerability

    Post summary

    The article announces Microsoft 365 Copilot and Edge vulnerabilities (CVE‑2026‑26129/26164/33111) that could lead to information leakage due to inadequate sanitization, but it does not include a PoC, exploit, or patch details.

    01000155
    489 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-40398 7.8 Windows リモート デスクトップ ・CVE-2026-41103 9.1 Jira と Confluence 用の Microsoft SSO プラグイン -対象外:10 件 ・CVE-2026-26129 7.5 M365 Copilot つづく…

    Post summary

    The post merely lists CVE identifiers with severity scores and affected products, without any additional technical, exploit, or mitigation information.

    10000107
    85 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    Microsoft just disclosed three info-disclosure flaws in Microsoft 365 Copilot, all CVSS 7.5, all patched server-side. CVE-2026-26129: improper neutralization of output (CWE-138) in Copilot. CVE-2026-26164: output injection (CWE-74) in Copilot. CVE-2026-33111: command injection (CWE-77) in Copilot Chat for Edge. Three separate output-sanitization bugs in one product, one disclosure window. The pattern matters more than any single fix.

    Post summary

    Microsoft announced it has disclosed three medium‑severity info‑disclosure flaws in Microsoft 365 Copilot, all involving output sanitization issues, and that server‑side patches have already been deployed.

    00000199
    574 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26129 Improper neutralization of special elements in M365 Copilot allows an unauthorized attacker to disclose information over a network. https://www.cve.org/CVERecord?id=CVE-2026-26129 ----- Traducción: CVE-2026-26129 No neutralización adecuada de elementos … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-26129 for M365 Copilot, detailing an improper neutralization flaw that could enable information disclosure, but it does not mention a PoC, exploit code, active exploitation, or patch.

    0000027
    76 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26129 Improper neutralization of special elements in M365 Copilot allows an unauthorized attacker to disclose information over a network. https://www.cve.org/CVERecord?id=CVE-2026-26129

    Post summary

    The post announces CVE-2026-26129, describing an information disclosure flaw in M365 Copilot.

    00000295
    57.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    21:31 UTC: CVE-2026-26129 disclosed. ‼️🚨 Microsoft just patched three critical M365 Copilot data leak vulnerabilities. All three are network-reachable, unau

    Post summary

    Microsoft has released patches for three critical M365 Copilot data leak vulnerabilities, including CVE-2026-26129, which were network-reachable. No proof of concept or active exploitation details are disclosed.

    0000071
    197 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    ⚠️Microsoft patched 3 critical Copilot flaws: CVE-2026-26129, CVE-2026-26164 and CVE-2026-33111. The bugs could expose sensitive enterprise data in Microsoft 365 Copilot and Copilot Chat via injection and command injection attacks. https://msrc.microsoft.com/update-guide/vulnerability #Microsoft365

    Post summary

    Microsoft has patched three critical Copilot CVEs (CVE‑2026‑26129, CVE‑2026‑26164, CVE‑2026‑33111), noting potential injection vulnerabilities but providing no evidence of exploitation or PoC.

    0000061
    728 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    ⚠️ الثغرات الثلاث قد تسبب تسريب معلومات من بيئة Microsoft 365. الأولى CVE-2026-26129 ناتجة عن ضعف في التعامل مع Special Elements داخل M365 Copilot. الثانية CVE-2026-26164 عبارة عن Output Injection في مكون داخلي.

    Post summary

    The text briefly announces two CVEs that could lead to data leakage in Microsoft 365, providing limited technical description but no PoC, exploit, or mitigation details.

    00000239
    49.1K followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-26129 | M365 Copilot Information Disclosure Vulnerability | Rahsi Framework™ https://www.aakashrahsi.online/post/cve-2026-26129 https://t.co/mlnCh58yeX

    Post summary

    The text announces CVE-2026-26129 as an information‑disclosure flaw in M365 Copilot, but does not provide PoC, exploit, or patch details.

    0000049
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-26129 Information Disclosure in Microsoft 365 Copilot via Improper Special Element Neutralization https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26129

    Post summary

    CVE-2026-26129 is an information disclosure vulnerability in Microsoft 365 Copilot caused by improper neutralization of special elements, as referenced in the linked vulnerability report.

    0000064
    4.0K followersView on X
  • WindowsForum@windowsforum
    Patch

    🔥 CVE-2026-26129: Microsoft says “no action needed” because they already put out the fire… but it happened in Copilot Business Chat. Translation: your AI chat’s had secrets. #Windows #Security https://windowsforum.com/threads/cve-2026-26129-critical-info-leak-fixed-in-microsoft-365-copilot-business-chat.416850/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #CloudSecurity #InformationDisclosure #Microsoft365Copilot https://t.co/bEZTFouveV

    Post summary

    Microsoft has already fixed CVE‑2026‑26129 as an info‑leak in Copilot Business Chat, stating no further action is required.

    0000059
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_copilot_chat---

Explore more