CVE-2026-26137Disclosure(microsoft / 365_copilot_chat)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_copilot_chat

Threat summary

  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-03-19); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
365_copilot_chat

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-03-19: 2Mentions · 2026-03-20: 2Mentions · 2026-03-22: 1Mentions · 2026-03-24: 2Mentions · 2026-03-26: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-24: 203-1903-2003-2203-2403-26
Signal classification2 categories
Disclosure
787.5%
General
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-192
Disclosure2
2026-03-202
Disclosure2
2026-03-221
Disclosure1
2026-03-242
Disclosure2
2026-03-261
General1
Full discourse8 posts
  • dbugs@ptdbugs
    Disclosure

    Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability CVE: CVE-2026-26137 PT-Identifier: PT-2026-26355 Vendor: Microsoft Product: Microsoft 365 Copilot's Business Chat CVSS: 8.9 Credits: n/a Description: Server-side request forgery (ssrf) in Microsoft 365 Copilot's Business Chat allows an authorized attacker to elevate privileges over a network. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-26137 • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26137 #dbugs_vuln

    Post summary

    The post announces the CVE-2026-26137 vulnerability in Microsoft 365 Copilot Business Chat, describing it as a server‑side request forgery that can elevate privileges, and provides references to vendor advisory pages but no PoC or exploit code.

    0102155
    649 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 3.19 Microsoft 365 Copilot BizChat の特権昇格の脆弱性 CVE-2026-26137 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26137

    Post summary

    Microsoft advertises a privilege‑escalation vulnerability in its 365 Copilot BizChat (CVE‑2026‑26137) and links to its advisory, but provides no PoC, exploit, or patch details.

    1010094
    88 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-26137 Security Vulnerability 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 9.9 / 8.6 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2036265956146815470

    Post summary

    CVE-2026-26137 is a privacy‑escalation vulnerability disclosed with emergency severity and high CVSS scores; no exploit, PoC, or patch information is included.

    1000046
    88 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-26137 - Microsoft - Microsoft 365 Copilot's Business Chat - https://www.redpacketsecurity.com/cve-alert-cve-2026-26137-microsoft-microsoft-365-copilot-s-business-chat/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-26137 #microsoft #microsoft-365-copilot-s-business-chat

    Post summary

    The post merely announces CVE-2026-26137 for Microsoft 365 Copilot's Business Chat without supplying technical details, exploit code, or mitigation information.

    0001058
    3.6K followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-26137 | Microsoft 365 Copilot BizChat Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-26137 https://t.co/PS29ZQXnyJ

    Post summary

    The tweet merely lists the CVE and links to an external post; no substantive details, exploits, or mitigations are disclosed in the provided text.

    0000052
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26137 Server-side request forgery (ssrf) in Microsoft 365 Copilot's Business Chat allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-26137

    Post summary

    CVE-2026-26137 is a server‑side request forgery vulnerability in Microsoft 365 Copilot's Business Chat that permits authorized attackers to elevate privileges on the network.

    00000178
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26137 - High Server-side request forgery (ssrf) in Microsoft 365 Copilot's Business Chat allows an authorized attacker to elevate privileges over a network. https://www.thehackerwire.com/vulnerability/CVE-2026-26137/ https://t.co/891L8iKgda

    Post summary

    CVE-2026-26137 is a high‑severity SSRF flaw in Microsoft 365 Copilot's Business Chat that can lead to privilege escalation; the post announces the vulnerability without providing PoC, exploit, patch, or evidence of active exploitation.

    0000045
    137 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26137: HIGH] Server-side request forgery (ssrf) in Microsoft 365 Copilot's Business Chat allows an authorized attacker to elevate privileges over a network.#cve,CVE-2026-26137,#cybersecurity https://cvefind.com/CVE-2026-26137

    Post summary

    An announcement of a high‑severity Server‑Side Request Forgery in Microsoft 365 Copilot’s Business Chat, noting potential privilege escalation, with no PoC, exploit, or patch details provided.

    0000061
    603 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_copilot_chat---

Explore more