CVE-2026-26136Disclosure(microsoft / copilot)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • copilot

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-24)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
copilot

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-20: 1Mentions · 2026-03-22: 1Mentions · 2026-03-24: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-24: 203-2003-2203-24
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-201
General1
2026-03-221
Disclosure1
2026-03-242
Disclosure2
Full discourse4 posts
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 3.19 Copilot の情報漏えいの脆弱性 CVE-2026-26136 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26136

    Post summary

    Microsoft disclosed CVE-2026-26136 as a Copilot information‑leak vulnerability, but no PoC, exploit, or patch details are included.

    1010065
    88 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-26136 Security Vulnerability 影響: 情報漏えい 最大深刻度: 緊急 CVSS:3.1 6.5 / 5.7 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: https://x.com/kawn2020/status/2036265161636585587

    Post summary

    The tweet announces Microsoft CVE-2026-26136 as an information‑leak vulnerability with urgent severity and CVSS scores of 6.5/5.7, but provides no evidence of exploits, patches, or active attacks.

    1000033
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26136 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over … https://www.cve.org/CVERecord?id=CVE-2026-26136

    Post summary

    The post announces CVE‑2026‑26136 as a command injection issue in Microsoft Copilot that could allow unauthorized information disclosure, but provides no evidence of exploitation, PoC, or patch.

    00010199
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-26136 Command Injection Vulnerability in Microsoft Copilot Enables Info... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26136 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post identifies CVE-2026-26136 as a command injection vulnerability in Microsoft Copilot but provides no additional details such as exploit code, active usage, or patches.

    0000038
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftcopilot---

Explore more