{"id":12734,"date":"2026-05-09T10:03:44","date_gmt":"2026-05-09T10:03:44","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/09\/critical-microsoft-365-copilot-vulnerabilities-expose-sensitive-information\/"},"modified":"2026-05-09T10:03:44","modified_gmt":"2026-05-09T10:03:44","slug":"critical-microsoft-365-copilot-vulnerabilities-expose-sensitive-information","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/09\/critical-microsoft-365-copilot-vulnerabilities-expose-sensitive-information\/","title":{"rendered":"Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information"},"content":{"rendered":"<p>    Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Microsoft has disclosed and fully remediated three critical information disclosure vulnerabilities affecting <a href=\"https:\/\/cybersecuritynews.com\/microsoft-365-copilot-bug\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft 365 Copilot<\/a> and Copilot Chat in Microsoft Edge, all released on May 7, 2026, requiring no action from end users or administrators.<\/p>\n<p>Microsoft\u2019s Security Response Center published advisories for CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111 as part of its ongoing commitment to transparency in its cloud services.<\/p>\n<p>All three vulnerabilities carry a Critical severity rating and fall under the Information Disclosure impact category.<\/p>\n<p>Microsoft has already fully mitigated all three flaws on its end, consistent with its cloud CVE transparency initiative outlined in the \u201cToward Greater Transparency: Unveiling Cloud Service CVEs\u201d program.<\/p>\n<h2 class=\"wp-block-heading\" id=\"technical-breakdown\"><strong>Microsoft 365 Copilot Vulnerabilities<\/strong><\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-26129\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-26129 affects<\/a> Microsoft 365 Copilot\u2019s Business Chat. The vulnerability stems from improper neutralization of special elements in output used by a downstream component, potentially allowing an unauthorized attacker to disclose sensitive information over a network.<\/p>\n<p>Although full CVSS metrics were not published for this CVE, the critical severity label reflects the high confidentiality risk inherent in Copilot\u2019s enterprise data access model.<\/p>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-26164\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-26164<\/a> also targets M365 Copilot and is classified under CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component \u2014 Injection).<\/p>\n<p>The attack vector is network-based, requires no privileges or user interaction, and has a high confidentiality impact. The exploitability assessment is rated \u201cExploitation Less Likely,\u201d and exploit code maturity is listed as unproven.<\/p>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-33111\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-33111<\/a> affects Copilot Chat embedded in Microsoft Edge and is classified under CWE-77 (Improper Neutralization of Special Elements Used in a Command \u2014 Command Injection).<\/p>\n<p>It shares the same CVSS score of 7.5 \/ 6.5 (temporal) as CVE-2026-26164, with an identical attack profile: network-accessible, no privileges required, no user interaction, and high confidentiality impact.<\/p>\n<p>This is particularly concerning given the widespread deployment of Edge across enterprise environments.<\/p>\n<p>All three vulnerabilities highlight a growing attack surface unique to AI-powered productivity tools.<\/p>\n<p>Because M365 Copilot aggregates and processes vast amounts of organizational data, including emails, documents, and Teams conversations, weaknesses in how it handles special elements or injected commands can allow sensitive information to leak across trust boundaries.<\/p>\n<p>In environments where Copilot has broad access to corporate data sources, the impact could include exposure of intellectual property, confidential communications, or restricted internal records.<\/p>\n<p>Microsoft credited Estevam Arantes of Microsoft for discovering both CVE-2026-26129 and CVE-2026-26164, with additional credit to independent researcher 0xSombra for CVE-2026-26164.<\/p>\n<p>No acknowledgment was listed for CVE-2026-33111. Microsoft confirmed that none of the three vulnerabilities were publicly disclosed or actively exploited prior to publication.<\/p>\n<p>Since all three are cloud-side vulnerabilities, Microsoft has already deployed mitigations at the service layer. Enterprises do not need to install patches or apply configuration changes.<\/p>\n<p>However, security teams are advised to review Copilot\u2019s data access permissions and enforce least-privilege principles to reduce exposure from any future similar flaws.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Cybercriminals now enter through your suppliers instead of your front door \u2013 <a href=\"https:\/\/www.manageengine.com\/products\/desktop-central\/webinars\/uk-cybersecurity-essentials-2026.html?utm_source=CSN&amp;utm_medium=TPS-mailer&amp;utm_campaign=UKCSW\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Free Webinar<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsoft-365-copilot-vulnerabilities-data\/\">Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsoft-365-copilot-vulnerabilities-data\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information Microsoft has disclosed and fully remediated three critical information disclosure vulnerabilities affecting Microsoft 365 Copilot and Copilot Chat in Microsoft Edge, all released on May 7, 2026, requiring no action from end users or administrators. Microsoft\u2019s Security Response Center published advisories for CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111 as [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-12734","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12734"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12734"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12734\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12734"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12734"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12734"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}