CVE-2026-26133Disclosure(microsoft / 365_copilot)

HIGHCVSS 7.1 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch microsoft 365_copilot systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_copilot
  • edge
  • excel
  • loop

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 7 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 11 signals
  • Disclosure: 8 classified signals
  • Peaked 5d ago at 5 mentions (2026-03-13); latest day: 1
  • 15 total mentions across 7 days

Affected systems

Vendors
Products
365_copilotedgeexcellooponenoteoutlookpower_bipowerpointteamsword

1 version affected across 10 products

Deep dive

Activity timeline15 mentions / 7d
01345Mentions · 2026-03-12: 3Mentions · 2026-03-13: 5Mentions · 2026-03-16: 2Mentions · 2026-03-17: 1Mentions · 2026-03-19: 2Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1PoC Mentioned / Linked · 2026-03-12: 1Active Exploitation · 2026-03-13: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-12: 3Technical Details · 2026-03-13: 3Technical Details · 2026-03-16: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 103-1203-1303-1603-1703-1903-2303-24
Signal classification4 categories
Disclosure
853.3%
Patch
533.3%
Active Exploitation
16.7%
General
16.7%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-123
Disclosure2Patch1
2026-03-135
Active Exploitation1Disclosure4
2026-03-162
Disclosure1Patch1
2026-03-171
General1
2026-03-192
Disclosure1Patch1
2026-03-231
Patch1
2026-03-241
Patch1
Full discourse15 posts
  • 📕「マルウエアの教科書」著者 | 吉川孝志 | 増補改訂版🌟発売中@MalwareBibleJP
    Patch

    Microsoft 365 Copilotのメール要約機能に、フィッシングコンテンツをCopilotのUIごと偽装できるプロンプトインジェクションの脆弱性(CVE-2026-26133)が見つかり、パッチが公開されました。 攻撃者がメール本文の末尾に、人間の目には見えにくいがLLMには読める指示テキストを仕込んでおくと、受信者がCopilotで要約を実行した際に、Microsoftのセキュリティ警告に似せた偽のセキュリティ警告が要約内に生成されます。 添付ファイルもマクロも使わず、Copilot自身の文面と体裁で偽の警告を語らせるのが特徴。 2025年に報告されたEchoLeak(CVE-2025-32711)はデータの外部送信が主な脅威でしたが、今回の焦点はフィッシングです。 Copilotの出力を「システムが出した正規の通知」だとユーザーが思い込むことを突いています。 不審なメール本文を警戒する教育は浸透してきましたが、AI要約パネルの出力まで疑うという発想はまだ一般的ではありません。 【攻撃手口の概要】 ・CVE-2026-26133はPermiso Securityが発見し、2026年3月12日にMicrosoftがCVEを公開。Copilotがメールの全文を生テキストとして取り込む際、末尾の指示的テキストをそのまま命令として処理してしまう信頼境界の問題 ・Outlookの要約ボタン、Outlookのサイドパネル(Copilotペイン)、Teams Copilotの3つの入口でテストが実施され、安全性に明確な差。Outlookの要約ボタンは短い攻撃テキストを検知・拒否したが、長く自然な文面を混ぜると挙動が不安定に。Outlookのサイドパネルはデフォルトでより慎重に振る舞い注入を無視・拒否する傾向があったが、メールクライアントによっては従う場合もあった。Teams Copilotは最も従順で、正常な要約のあとに攻撃者の仕込んだ内容を出力する挙動が確認された ・ユーザーにとってCopilotはどのインターフェースでも同じ存在であり、安全性の差を意識して使い分ける人はほぼいない。答えが返ってくるほうに流れるため、最も脆弱な面が実質的な攻撃面になる ・Copilotの検索範囲がTeamsの会話、OneDriveのファイル、SharePointのドキュメントにまで及ぶ環境では、注入されたプロンプトが社内情報を取得し、攻撃者が用意したリンクに埋め込む形で外部送信する経路も確認されたとのこと。ただし、これが確実なデータ窃取になるかはSafe Links、DLP、秘密度ラベル、ユーザー権限などの制御状況に依存するとPermiso自身が留保している。ユーザーは「アカウントを保護してください」のような偽ボタンを1回クリックするだけで、自分が何かをコピーした自覚なく情報が漏れる ・Microsoftは1月28日に内部で再現を確認、2月17日から段階的に修正を展開し、3月11日に全対象面への適用が完了 メール由来のプロンプトインジェクション自体はEchoLeakで知られた攻撃クラスですが、入口ごとの安全性のばらつきと、AIの体裁を借りたフィッシングの有効性を具体的に示した報告です。 パッチは適用済みですが、同種のAI要約ツールを導入している環境では、AIの出力もシステム通知と同じように鵜呑みにしない意識づけが必要です。 https://permiso.io/blog/copilot-prompt-injection-ai-email-phishing

    Post summary

    Microsoft 365 Copilot's email summary feature had a prompt‑injection flaw (CVE‑2026‑26133) that lets attackers inject hidden instructions to generate fake phishing warnings; a patch has been released, and the blog post provides technical details of the vulnerability.

    02118112.2K
    5.2K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Microsoft Copilot の脆弱性 CVE-2026-26133 が FIX:Email/Teams 要約を介したフィッシング https://iototsecnews.jp/2026/03/12/microsoft-copilot-email-and-teams-summarization-vulnerability-enables-phishing-attacks/ Microsoft Copilot の利便性を逆手に取った攻撃を可能にする、AI セキュリティの脆弱性 CVE-2026-26133 が公開されました。この問題の原因は、外部から届いたメールという信頼できないコンテンツを AI が処理する際に、その中に埋め込まれている悪意の指示を、システムからの命令と誤認して実行してしまう Cross-Prompt Injection Attack (XPIA) にあります。 この攻撃は、従来のようにウイルス・ファイルを送りつけるのではなく、メール本文に自然な文章として攻撃用プロンプトを隠し持ちます。Copilot が、そのメールを要約しようとすると、埋め込まれた指示が発動し、Microsoft の公式セキュリティ・アラートを装う偽の通知が要約パネル内に表示されてしまいます。 ここで最も危険なのは、信頼移転と呼ばれる現象です。ユーザーは、不審なメール本文を警戒しますが、Microsoft の純正ツールが生成した要約画面に表示される内容は、システムによる公式な通知だと信じ込んでしまいます。それにより、フィッシングの成功率が劇的に高まります。なお、この脆弱性 CVE-2026-26133 は、2026年3月の Patch Tuesday の直後に公開されたようです。 #AI #ML #Copilot #CVE202626133 #Microsoft #PromptInjection

    Post summary

    The article announces CVE‑2026‑26133, outlines how Cross‑Prompt Injection in Microsoft Copilot enables phishing via email/Teams summarization, and notes that a fix was deployed shortly after Patch Tuesday.

    02000205
    484 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『This isn’t a “Microsoft-only” issue. It’s a broader class of problems known as Cross Prompt Injection Attacks (XPIA),』 CVE-2026-26133 CO-PILOT, DISENGAGE AUTOPHISH: The New Phishing Surface Hiding Inside AI Email Summaries https://permiso.io/blog/copilot-prompt-injection-ai-email-phishing

    Post summary

    The content announces CVE‑2026‑26133, describing it as a Cross Prompt Injection Attack, but offers no PoC, exploit code, active‑exploitation evidence, patch, or in‑depth technical details, effectively acting as a general disclosure.

    00011522
    6.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚠️ CVE-2026-26133: M365 Copilot Information Disclo... AI prompt injection hitting M365 Copilot across mobile + Edge - 7.1 CVSS with network-based info disclosure makes this ... https://zerodaysignal.com/vulnerability/CVE-2026-26133 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new Microsoft 365 Copilot vulnerability (CVE‑2026‑26133) that allows prompt injection‑based information disclosure over the network has been announced, with a CVSS score of 7.1.

    1000073
    151 followersView on X
  • Blue Team France E/ACC@Blueteamfrance
    Patch

    🚨 #CVE-2026-26133 (Microsoft Edge) (browser vulnerability) ➡️ Data leakage via crafted content ➡️ Affects mobile (iOS / Android Edge) 📅 Mar 2026 🔍 Hunt: unusual web requests, 🛡️ Update browser ASAP (>= 145.3800.99) 🔗 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26133 #SOC

    Post summary

    The tweet announces a data‑leakage vulnerability in Microsoft Edge with a clear patch recommendation and update path, but offers no proof of exploitation or detailed technical description beyond the general leak scenario.

    0000076
    6 followersView on X
  • VaultXCircle Labs@VaultXCircle
    Patch

    @0dayPublishing CVE-2026-26133 shows Microsoft can patch their own pipeline. The scarier version: thousands of startups building AI products that accept file uploads with zero scanning. Hidden instructions in cells, invisible text in PDFs, EXIF payloads — all landing in the LLM context. Most devs don't know this attack surface exists.

    Post summary

    The tweet highlights that Microsoft has patched CVE-2026-26133 and warns AI startups that accept unscanned file uploads could be exposed to hidden instruction-based attacks.

    0000031
    8 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-26133: M365 Copilot AI Command Injection - What It Means for Your Business and How to Respond https://hubs.li/Q047xSQB0

    Post summary

    An article announces CVE-2026-26133, a command injection flaw in Microsoft 365 Copilot AI, and outlines business response measures.

    0000025
    29 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-26133 - Microsoft - Microsoft 365 Copilot for Android - https://www.redpacketsecurity.com/cve-alert-cve-2026-26133-microsoft-microsoft-365-copilot-for-android/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-26133 #microsoft #microsoft-365-copilot-for-android

    Post summary

    A CVE alert is posted for CVE-2026-26133 affecting Microsoft 365 Copilot for Android, with a link to a reporting site, but no further technical or exploit details are included.

    00000104
    3.6K followersView on X
  • kawn@kawn2020
    Patch

    #microsoftupdate #securityupdate #Edge マイクロソフトが Microsoft Edge for Android and iOS Stable Channel (Version 145.3800.99) をリリース. CVE ベースで脆弱性 1 件に対処. ・CVE-2026-26133 https://x.com/kawn2020/status/2033470727836565978

    Post summary

    Microsoft released Edge for Android and iOS version 145.3800.99 to patch CVE-2026-26133.

    00000126
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26133 AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. https://www.cve.org/CVERecord?id=CVE-2026-26133

    Post summary

    A brief disclosure of CVE‑2026‑26133, noting an AI command injection in M365 Copilot that could lead to information disclosure over a network.

    00000149
    56.7K followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    🎙️ RadioCSIRT Ep.596 – Édition du vendredi 13 mars 2026 Cinq sujets. Un fil rouge : des Zero-Day activement exploités, des données sensibles exposées et le renforcement des capacités CSIRT en Afrique. 🔴 CISA KEV : trois nouvelles entrées en exploitation active. CVE-2026-3909 (Google Skia – Out-of-Bounds Write), CVE-2026-3910 (Google Chromium V8 – implémentation incorrecte), CVE-2025-68613 (n8n – exécution de code via ressources dynamiques). 🔴 Google Chrome : patch hors cycle en urgence. Deux Zero-Day corrigés, exploitables à distance via simple visite d'une page malveillante. Versions protégées : 146.0.7680.75/76 sur Windows et macOS, 146.0.7680.75 sur Linux. 🔴 CERT-FR : trois avis publiés ce vendredi. CERTFR-2026-AVI-0294 – CVE-2026-26133, atteinte à la confidentialité dans Microsoft Office sur Android, iOS et macOS. CERTFR-2026-AVI-0285 – CVE-2025-13462, vulnérabilité dans CPython, nature non précisée. CERTFR-2026-AVI-0289 – multiples failles dans le noyau Linux d'Ubuntu 22.04 LTS et 24.04 LTS, quatre CVE référencées. 🔴 Quittr : misconfiguration Firebase expose pendant plusieurs mois les données sensibles de plus de 600 000 utilisateurs d'une application de lutte contre la dépendance à la pornographie. Environ 100 000 profils de mineurs concernés. Alerte initiale ignorée depuis septembre 2025. 🔴 FIRST – African Regional Liaison : bilan deux ans. 1 210 professionnels soutenus, 50 initiatives, 33 pays, 70 CSIRTs engagés. Programme Train-the-Trainer actif dans sept pays africains. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-596-votre-actualite-cybersecurite-du-vendredi-13-mars-2026/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #ThreatIntelligence #CTI #CISA #KEV #Chrome #ZeroDay #Skia #V8 #Chromium #Quittr #Firebase #DataLeak #DataBreach #MicrosoftOffice #Python #CPython #Ubuntu #Linux #CERTFR #FIRST #AfricaCyber #CSIRT #n8n #CVE #InfoSec #CERT #SOC #CISO #VOC #Patch

    Post summary

    The report announces that several zero‑day CVEs are currently being exploited in the wild, while vendors have released emergency patches and advisories to mitigate the threats.

    0000098
    412 followersView on X
  • Bits, Bytes, and Bourbon@DecryptedTech
    Disclosure

    Fun!! Happy Friday https://windowsforum.com/threads/cve-2026-26133-microsoft-365-copilot-information-disclosure-and-the-confidence-signal.404852/

    Post summary

    The post simply links to a forum thread discussing CVE‑2026‑26133 with no further details or technical content.

    0000073
    1.7K followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-26133 | M365 Copilot Information Disclosure Vulnerability https://www.aakashrahsi.online/post/cve-2026-26133 https://t.co/3Vz5VNXPfk

    Post summary

    The tweet announces CVE-2026-26133, an Information Disclosure flaw in M365 Copilot, and directs readers to a blog post for further details.

    0000040
    2 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    CVE-2026-26133 shows how cross-prompt injection in Microsoft 365 Copilot email summaries could enable AI-assisted phishing, allowing attacker-controlled email content to manipulate trusted AI-generated summaries and prompt users into malicious actions. https://permiso.io/blog/copilot-prompt-injection-ai-email-phishing

    Post summary

    The article outlines CVE‑2026‑26133 as a cross‑prompt injection flaw in Microsoft 365 Copilot that could be leveraged for AI‑assisted phishing attacks.

    0000054
    242 followersView on X
  • NeuraCyb Intelligence@NeuraCybSecLabs
    Disclosure

    Microsoft Copilot Email Summaries Exposed to Prompt Injection Phishing Risk (CVE-2026-26133) https://www.neuracybintel.com/articles/microsoft-copilot-email-summaries-exposed-to-prompt-injection-phishing-risk-cve-2026-26133?utm_source=twitter&utm_medium=social&utm_campaign=articles_share

    Post summary

    A new vulnerability (CVE‑2026‑26133) in Microsoft Copilot email summaries allows prompt injection phishing, with vulnerability details disclosed but no exploit, patch, or PoC mentioned.

    0000045
    5 followersView on X
CPE platform detail20 entries

20 of 20 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_copilot-android-
Appmicrosoft365_copilot-iphone_os-
Appmicrosoftedge-android-
Appmicrosoftedge-iphone_os-
Appmicrosoftexcel-android-
Appmicrosoftexcel-iphone_os-
Appmicrosoftloop-iphone_os-
Appmicrosoftonenote-android-
Appmicrosoftonenote-iphone_os-
Appmicrosoftoutlook-android-
Appmicrosoftoutlook-iphone_os-
Appmicrosoftoutlook-macos-
Appmicrosoftpower_bi-android-
Appmicrosoftpower_bi-iphone_os-
Appmicrosoftpowerpoint-android-
Appmicrosoftpowerpoint-iphone_os-
Appmicrosoftteams-android-
Appmicrosoftteams-iphone_os-
Appmicrosoftword-android-
Appmicrosoftword-iphone_os-

Explore more