CVE-2026-33111Disclosure(microsoft / copilot_chat)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft copilot_chat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • copilot_chat

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 11 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 3 mentions (2026-05-08); latest day: 1
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
copilot_chat

1 version affected across 1 product

Deep dive

Activity timeline12 mentions / 6d
01223Mentions · 2026-05-08: 3Mentions · 2026-05-09: 3Mentions · 2026-05-10: 3Mentions · 2026-05-12: 1Mentions · 2026-05-15: 1Mentions · 2026-05-19: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-09: 2Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-08: 3Technical Details · 2026-05-09: 2Technical Details · 2026-05-10: 3Technical Details · 2026-05-12: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-19: 105-0805-0905-1005-1205-1505-19
Signal classification3 categories
Disclosure
758.3%
Patch
325.0%
General
216.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-083
Disclosure2Patch1
2026-05-093
General1Patch2
2026-05-103
Disclosure2General1
2026-05-121
Disclosure1
2026-05-151
Disclosure1
2026-05-191
Disclosure1
Full discourse12 posts
  • International Cyber Digest@IntCyberDigest
    Patch

    ‼️🚨 Microsoft just patched three critical M365 Copilot data leak vulnerabilities. All three are network-reachable, unauthenticated, and zero-click. M365 Copilot Business Chat usually has access to a tenant's SharePoint, OneDrive, Outlook, Teams, and more. ▪️ CVE-2026-26129 (M365 Copilot Business Chat): improper neutralization of special elements. Information disclosure. ▪️ CVE-2026-26164 (M365 Copilot Business Chat): output injection into a downstream component. Information disclosure. ▪️ CVE-2026-33111 (Copilot Chat in Microsoft Edge): command injection. Information disclosure. Copilot was server-side patched, so no customer action is required. Microsoft has published no technical details and there is no PoC.

    Post summary

    Microsoft has released server‑side patches for three critical M365 Copilot data leak CVEs with no PoC or active exploitation reported, and no customer action is required.

    1188438614537.7K
    184.6K followersView on X
  • Kruptos@KuptoKosmos
    Patch

    🚨💻🗃️ MICROSOFT COPILOT... LES DONNÉES D’ENTREPRISE ÉTAIENT OPEN BAR AVEC 3 FAILLES ZERO-CLICK !! 🤫 Le 7 mai 2026, Microsoft a silencieusement patché 3 vulnérabilités critiques dans M365 Copilot (Business Chat) et Copilot Chat dans Edge Les CVE : 2026-26129, 2026-26164 et 2026-33111 Zero-click. Zéro interaction... 🤨 Un attaquant distant, même pas authentifié, pouvait littéralement se servir comme à l’open bar dans tes données d’entreprise ! Pendant ce temps, Copilot continuait tranquillement à fouiller dans ton Graph : mails Outlook, docs SharePoint/OneDrive, Teams, calendriers, contrats, données RH, secrets commerciaux… Tout y passait ➡️ Ces 3 failles sont du même moule : injection dans la sortie (output injection/command injection) Clairement... Copilot crachait du contenu mal filtré, et un composant en aval (interne Microsoft) le prenait au mot et balançait des données sensibles qu’il n’aurait JAMAIS dû exposer !! 👉 CVE-2026-26129 & 26164 (Business Chat) 👉 CVE-2026-33111 (Copilot dans Edge) Score CVSS 7.5, mais dans la vraie vie c'est critique absolue parce que c’est réseau, zéro auth, et que Copilot a accès à tout ce qui fait le nerf de la guerre en entreprise ! ⚠️ Tu n’as rien à faire. Tu bosses normalement, Copilot interroge le Graph pour "t’aider"... et bam, une requête craftée depuis l’extérieur suffit Pas besoin d’infecter un poste, pas besoin d’un mail piégé. Juste une IA trop puissante avec des filtres de sortie faits au lance-pierre ! 🤦‍♂️ Résultat n’importe quelle boîte qui avait déployé Copilot devenait une piñata de données ouverte 24/7 Microsoft a tout corrigé côté serveur (patch automatique, rien à faire pour les admins). Pas de PoC public, pas de détails techniques (on connaît la chanson) Mais c'était clairement open bar total !!! C’est encore une fois le grand classique Microsoft : on donne un super-pouvoir à une IA qui voit absolument tout et on oublie de sécuriser les sorties Comme la mémoire dump d’Edge l’autre jour 🙄 En 2026, on confie nos données les plus sensibles à des boîtes qui considèrent que "c’est normal que ça fuite un peu" !! Si t’es en entreprise et que vous roulez sur Copilot Business vérifie que le patch est bien propagé Et sinon… tu sais ce qu’il te reste à faire : logs en mode parano et œil sur tes données ! Bref... on continue de payer cher pour des "outils intelligents" qui nous rendent surtout plus vulnérables. #CyberSecurity #Microsoft 🤡

    Post summary

    The post reports three critical zero‑click Microsoft Copilot CVEs that were patched automatically, detailing output injection vulnerabilities and emphasizing that no admin action is required, yet it offers no PoC or evidence of active exploitation.

    625450162.9K
    8.6K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    الثالثة CVE-2026-33111 عبارة عن Command Injection في Copilot Chat داخل Microsoft Edge. ⚠️ الخطورة هنا سببها موقع Copilot داخل بيئة العمل.

    Post summary

    The post states that CVE-2026-33111 is a Command Injection vulnerability in Copilot Chat on Microsoft Edge, highlighting potential risk in a workplace setting.

    10010160
    49.0K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Microsoft 365 Copilot の脆弱性 CVE-2026-26129/26164/33111 が FIX:情報漏洩の恐れ https://iototsecnews.jp/2026/05/09/critical-microsoft-365-copilot-vulnerabilities-expose-sensitive-information/ Microsoft の AI ツール Copilot に見つかった、情報漏洩の脆弱性について解説する記事です。問題の原因は、 AI が出力したコマンドを実行する際などに、特殊要素に対する適切な無害化 (サニタイズ) が行われなかったことにあります。 具体的には、Copilot の CVE-2026-26129/ CVE-2026-26164 と、 Edge の CVE-2026-33111 といった脆弱性により、 リモートの攻撃者が組織の機密情報を盗み出せるリスクが生じていました。ご利用のチームは、ご注意ください。 #CVE202626129 #CVE202626164 #CVE202633111 #Microsoft365Copilot #Vulnerability

    Post summary

    The article discloses that Microsoft 365 Copilot CVE‑2026‑26129, CVE‑2026‑26164, and Edge CVE‑2026‑33111 let remote attackers exfiltrate sensitive information due to lack of sanitization of AI‑generated commands, though no PoC, exploit code, patch, or proof of active exploitation is provided.

    01000155
    489 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    Microsoft just disclosed three info-disclosure flaws in Microsoft 365 Copilot, all CVSS 7.5, all patched server-side. CVE-2026-26129: improper neutralization of output (CWE-138) in Copilot. CVE-2026-26164: output injection (CWE-74) in Copilot. CVE-2026-33111: command injection (CWE-77) in Copilot Chat for Edge. Three separate output-sanitization bugs in one product, one disclosure window. The pattern matters more than any single fix.

    Post summary

    Microsoft publicly disclosed three CVSS 7.5 information‑disclosure vulnerabilities in 365 Copilot, all of which have been patched server‑side.

    00000199
    574 followersView on X
  • Vignesh_Pravin@VigneshVic23698
    Disclosure

    CVE-2026-33111: Microsoft Edge Copilot Chat Exposes User Data https://thecybrdef.com/cve-2026-33111-microsoft-edge-copilot-data-exposure/ #Microsoftplacements #Cybersecuirtynews #Cybersecurity

    Post summary

    The article announces the disclosure of CVE‑2026‑33111, indicating that Microsoft Edge Copilot Chat may expose user data, but provides no proof‑of‑concept, exploit details, or evidence of active exploitation.

    0000063
    2 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33111 Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose infor… https://www.cve.org/CVERecord?id=CVE-2026-33111 ----- Traducción: CVE-2026-33111 Neu… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-33111, a command injection flaw in Microsoft Edge's Copilot Chat, without indicating any active exploitation, PoC, or available patch.

    0000043
    76 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33111 Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose infor… https://www.cve.org/CVERecord?id=CVE-2026-33111

    Post summary

    The text merely identifies CVE‑2026-33111 as a command injection flaw in Copilot Chat (Microsoft Edge) without providing evidence of exploitation, solutions, or a PoC, so it is categorized as a general mention.

    00000286
    57.5K followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-33111: Microsoft Edge Copilot Chat Exposes User Data https://thecybrdef.com/cve-2026-33111-microsoft-edge-copilot-data-exposure/ #Microsoftplacements #Cybersecuirtynews #Cybersecurity

    Post summary

    The article announces Microsoft Edge Copilot Chat’s data‑exposure flaw (CVE‑2026‑33111) but provides no PoC, exploitation details, or patch information.

    0000037
    9 followersView on X
  • selva@SelvaKtm2
    General

    CVE-2026-33111: Microsoft Edge Copilot Chat Exposes User Data https://thecybrdef.com/cve-2026-33111-microsoft-edge-copilot-data-exposure/ #Microsoftplacements #Cybersecuirtynews #Cybersecurity https://t.co/xUXMZIQ0Gx

    Post summary

    The tweet announces CVE-2026-33111 and links to an external article but provides no technical insights, PoC, exploit, or patch information.

    0000036
    5 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    ⚠️Microsoft patched 3 critical Copilot flaws: CVE-2026-26129, CVE-2026-26164 and CVE-2026-33111. The bugs could expose sensitive enterprise data in Microsoft 365 Copilot and Copilot Chat via injection and command injection attacks. https://msrc.microsoft.com/update-guide/vulnerability #Microsoft365

    Post summary

    The tweet announces Microsoft’s patch release for three critical Copilot CVEs that could enable injection and command‑injection attacks to expose sensitive enterprise data.

    0000061
    728 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33111 Command Injection in Microsoft Edge Copilot Chat Enables Informat... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33111 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE-2026-33111, describing a command injection flaw in Microsoft Edge Copilot Chat, but it provides no proofs of exploitation, tools, active attacks, workarounds, or false‑positive claims.

    0000065
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftcopilot_chat-microsoft_edge-

Explore more