CVE-2026-26133: M365 Copilot Information Disclosure Vulnerability
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Other sources
M365 Copilot Information Disclosure Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26133?
CVE-2026-26133 is categorized as a crucial vulnerability due to its potential to allow unauthorized information disclosure.
How do I fix CVE-2026-26133?
To mitigate CVE-2026-26133, users should update their affected Microsoft applications to the latest versions released by Microsoft.
What type of information can be disclosed due to CVE-2026-26133?
CVE-2026-26133 may allow unauthorized attackers to disclose sensitive information transmitted over a network.
Which Microsoft products are affected by CVE-2026-26133?
CVE-2026-26133 affects multiple Microsoft products including OneNote, PowerPoint, Excel, Teams, Outlook, and 365 Copilot for various operating systems.
Is there a known exploit for CVE-2026-26133?
As of now, there is no publicly known exploit specifically targeting CVE-2026-26133.