CVE-2026-26164Disclosure(microsoft / 365_copilot_chat)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft 365_copilot_chat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_copilot_chat

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-05-08); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
365_copilot_chat

1 version affected across 1 product

Deep dive

Activity timeline10 mentions / 6d
01234Mentions · 2026-05-07: 1Mentions · 2026-05-08: 4Mentions · 2026-05-09: 1Mentions · 2026-05-10: 2Mentions · 2026-05-15: 1Mentions · 2026-05-19: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-09: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-08: 3Technical Details · 2026-05-09: 1Technical Details · 2026-05-10: 2Technical Details · 2026-05-15: 1Technical Details · 2026-05-19: 105-0705-0805-0905-1005-1505-19
Signal classification3 categories
Disclosure
770.0%
Patch
220.0%
General
110.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-084
Disclosure2General1Patch1
2026-05-091
Patch1
2026-05-102
Disclosure2
2026-05-151
Disclosure1
2026-05-191
Disclosure1
Full discourse10 posts
  • International Cyber Digest@IntCyberDigest
    Patch

    ‼️🚨 Microsoft just patched three critical M365 Copilot data leak vulnerabilities. All three are network-reachable, unauthenticated, and zero-click. M365 Copilot Business Chat usually has access to a tenant's SharePoint, OneDrive, Outlook, Teams, and more. ▪️ CVE-2026-26129 (M365 Copilot Business Chat): improper neutralization of special elements. Information disclosure. ▪️ CVE-2026-26164 (M365 Copilot Business Chat): output injection into a downstream component. Information disclosure. ▪️ CVE-2026-33111 (Copilot Chat in Microsoft Edge): command injection. Information disclosure. Copilot was server-side patched, so no customer action is required. Microsoft has published no technical details and there is no PoC.

    Post summary

    Microsoft has released patches for three critical M365 Copilot data‑leak vulnerabilities; no technical details, PoC, or evidence of active exploitation were provided.

    1188438614537.7K
    184.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26164 Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose informa… https://www.cve.org/CVERecord?id=CVE-2026-26164

    Post summary

    The text is a general disclosure of CVE-2026-26164, describing an injection type vulnerability in M365 Copilot, with no evidence of PoC, active exploitation, patch, or debunking.

    00020337
    57.8K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Microsoft 365 Copilot の脆弱性 CVE-2026-26129/26164/33111 が FIX:情報漏洩の恐れ https://iototsecnews.jp/2026/05/09/critical-microsoft-365-copilot-vulnerabilities-expose-sensitive-information/ Microsoft の AI ツール Copilot に見つかった、情報漏洩の脆弱性について解説する記事です。問題の原因は、 AI が出力したコマンドを実行する際などに、特殊要素に対する適切な無害化 (サニタイズ) が行われなかったことにあります。 具体的には、Copilot の CVE-2026-26129/ CVE-2026-26164 と、 Edge の CVE-2026-33111 といった脆弱性により、 リモートの攻撃者が組織の機密情報を盗み出せるリスクが生じていました。ご利用のチームは、ご注意ください。 #CVE202626129 #CVE202626164 #CVE202633111 #Microsoft365Copilot #Vulnerability

    Post summary

    The article discloses three Microsoft 365 Copilot/Edge CVEs that could cause information leakage via unsanitized AI output, but it provides no proof of concept, exploit code, or patch information, nor does it report active exploitation.

    01000155
    489 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    Microsoft just disclosed three info-disclosure flaws in Microsoft 365 Copilot, all CVSS 7.5, all patched server-side. CVE-2026-26129: improper neutralization of output (CWE-138) in Copilot. CVE-2026-26164: output injection (CWE-74) in Copilot. CVE-2026-33111: command injection (CWE-77) in Copilot Chat for Edge. Three separate output-sanitization bugs in one product, one disclosure window. The pattern matters more than any single fix.

    Post summary

    Microsoft announced three newly discovered CVEs affecting Microsoft 365 Copilot, each with CVSS 7.5 and server‑side patches already issued.

    00000199
    574 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26164 Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose informa… https://www.cve.org/CVERecord?id=CVE-2026-26164 ----- Traducción: CVE-2026-26164 Neu… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-26164 affecting Microsoft 365 Copilot, outlining an injection flaw via improper neutralization of special elements, with no evidence of active exploitation or remediation.

    0000038
    76 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    ⚠️Microsoft patched 3 critical Copilot flaws: CVE-2026-26129, CVE-2026-26164 and CVE-2026-33111. The bugs could expose sensitive enterprise data in Microsoft 365 Copilot and Copilot Chat via injection and command injection attacks. https://msrc.microsoft.com/update-guide/vulnerability #Microsoft365

    Post summary

    Microsoft has released patches for three critical Microsoft 365 Copilot CVEs that could lead to data exposure via injection and command injection.

    0000061
    728 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    ⚠️ الثغرات الثلاث قد تسبب تسريب معلومات من بيئة Microsoft 365. الأولى CVE-2026-26129 ناتجة عن ضعف في التعامل مع Special Elements داخل M365 Copilot. الثانية CVE-2026-26164 عبارة عن Output Injection في مكون داخلي.

    Post summary

    The post announces two new Microsoft 365 CVEs, describing their nature (a Special Elements handling flaw and an output injection issue) and their potential to leak information, but it offers no exploit details, patches, or evidence of active exploitation.

    00000239
    49.1K followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-26164 | M365 Copilot Information Disclosure Vulnerability | Rahsi Framework™ https://www.aakashrahsi.online/post/cve-2026-26164 https://t.co/HITh5okg3l

    Post summary

    The post announces a new information‑disclosure vulnerability (CVE‑2026‑26164) in Microsoft 365 Copilot, but it provides no exploit code, PoC, or patch details.

    0000081
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26164 Information Disclosure in Microsoft 365 Copilot via Output Injection Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26164

    Post summary

    The text announces CVE‑2026‑26164 as an information‑disclosure flaw in Microsoft 365 Copilot caused by output injection, but provides no details on exploits, patches, or active use.

    0000084
    4.0K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-26164: “information disclosure” in Copilot? Cool, so your AI coworker might accidentally spill the secrets. This matters because cloud trust is the real patch. https://windowsforum.com/threads/cve-2026-26164-microsoft-365-copilot-info-disclosure-and-why-confidence-matters.416847/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #InformationDisclosure #AiGovernance #Microsoft365Copilot #CveSecurity https://t.co/WqEXpCERZe

    Post summary

    The post announces CVE-2026-26164 as an information disclosure flaw in Microsoft 365 Copilot, with no PoC, exploit, or patch details shared.

    0000050
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_copilot_chat---

Explore more