
‼️🚨 Microsoft just patched three critical M365 Copilot data leak vulnerabilities. All three are network-reachable, unauthenticated, and zero-click. M365 Copilot Business Chat usually has access to a tenant's SharePoint, OneDrive, Outlook, Teams, and more. ▪️ CVE-2026-26129 (M365 Copilot Business Chat): improper neutralization of special elements. Information disclosure. ▪️ CVE-2026-26164 (M365 Copilot Business Chat): output injection into a downstream component. Information disclosure. ▪️ CVE-2026-33111 (Copilot Chat in Microsoft Edge): command injection. Information disclosure. Copilot was server-side patched, so no customer action is required. Microsoft has published no technical details and there is no PoC.
Post summary
Microsoft has released patches for three critical M365 Copilot data‑leak vulnerabilities; no technical details, PoC, or evidence of active exploitation were provided.









