CVE-2026-33102Disclosure(microsoft / 365_copilot)

MEDIUMCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft 365_copilot systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_copilot

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-04-24); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
365_copilot

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-04-24: 3Mentions · 2026-04-25: 1Mentions · 2026-04-27: 2Mentions · 2026-06-17: 1Active Exploitation · 2026-04-24: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-24: 3Technical Details · 2026-04-25: 1Technical Details · 2026-04-27: 1Technical Details · 2026-06-17: 104-2404-2504-2706-17
Signal classification3 categories
Disclosure
571.4%
Active Exploitation
114.3%
General
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-243
Active Exploitation1Disclosure2
2026-04-251
Disclosure1
2026-04-272
Disclosure2
2026-06-171
General1
Full discourse7 posts
  • Henrique Pereira@ikkebr
    General

    Earlier this year I set a goal to end the year with a couple CVEs to my name. So far, the year is going great: - CVE-2026-48579 (9.1 on MS Exchange) - CVE-2026-33102 (9.3 on M365 Copilot) - CVE-2026-21532 (8.2 on Azure Functions) - CVE-2026-44848 (9.4 on Portainer) - CVE-2026-55092 (8.0 on Trivy) Plus a plethora of other vulns I reported and got fixed without CVEs…

    Post summary

    The tweet lists five CVEs with CVSS scores and affected products but offers no detailed technical information, exploits, or patches, making it a general mention of discovered vulnerabilities.

    0202242.0K
    965 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Microsoft 365 Copilot CVE-2026-33102 is under active exploitation — attackers can elevate privileges through an open redirect vulnerability, risking user accounts. Patch now to prevent potential breaches. #NerdieNews #CyberSecurity #InfoSec #Ransomware #Malware #Microsoft https://t.co/ZvxrSEhPXs

    Post summary

    The tweet warns that Microsoft 365 Copilot CVE‑2026‑33102 is being actively exploited via an open‑redirect that can elevate privileges, and urges users to patch immediately.

    0002181
    68 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 4.23 Microsoft 365 Copilot の特権昇格の脆弱性 CVE-2026-33102 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33102

    Post summary

    Microsoft announces a new privilege escalation vulnerability in Microsoft 365 Copilot (CVE‑2026‑33102).

    10100160
    85 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-33102 「文書化された脆弱性を解決するために、お客様が取るべきアクションはあり…」 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 9.3 / 8.1 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2048691161301483568

    Post summary

    The tweet announces Microsoft’s security update for CVE-2026-33102, giving severity and CVSS details but no poC, exploit code, or evidence of active exploitation.

    1000088
    85 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33102 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-33102

    Post summary

    The text announces CVE-2026-33102, describing an open-redirect vulnerability in M365 Copilot that could allow privilege elevation, but offers no details on exploits, patches, or activity in the wild.

    00000128
    57.3K followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-33102 | Microsoft 365 Copilot Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-33102 https://t.co/1DQqDYN8Sk

    Post summary

    The tweet announces the existence of CVE‑2026‑33102, an elevation‑of‑privilege vulnerability in Microsoft 365 Copilot, and points to an external post for additional information.

    0000042
    1 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-33102 on Copilot isn’t “AI magic” — it’s “admin wishes.” If Microsoft says it’s elevation of privilege with high confidence, defenders should treat this like a real breach risk. https://windowsforum.com/threads/cve-2026-33102-copilot-elevation-of-privilege-and-why-microsoft-s-confidence-matters.414941/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #ElevationOfPrivilege #Microsoft365Copilot #Cve202633102 https://t.co/FLSrbKD6GP

    Post summary

    The post announces the newly disclosed CVE‑2026‑33102 as an elevation‑of‑privilege flaw in Microsoft Copilot, urging defenders to regard it as a real risk.

    00000103
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_copilot---

Explore more