CVE-2026-26133
M365 Copilot Information Disclosure Vulnerability
Description
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
In plain language
AI Worth attentionThis is an information-leak flaw in Microsoft 365 Copilot and related Microsoft apps; a typical small business should act by updating to the fixed versions as soon as possible.
CVE-2026-26133 is an information disclosure issue caused by an AI “command injection” weakness in Microsoft 365 Copilot, where an attacker can inject commands over the network and cause confidential data to be returned; exploitation is recorded as requiring user interaction and does not require authentication.
What to do now
- Check whether your business uses Microsoft 365 Copilot and the listed Microsoft apps (Edge, Excel, Loop, OneNote, Outlook, Power BI, PowerPoint, Teams, Word), and confirm they’re on the versions below.
- Update Microsoft 365 Copilot to 2.107.2.
- Update Microsoft Edge to 145.3800.99.
- Update Microsoft Excel and PowerPoint and Word to 2.106.2 (Excel/PowerPoint/Word as listed).
- Update Loop to 2.106.
- Update OneNote to 16.0.19725.20142.
- Update Outlook to 5.2605.0.
- Update Power BI to 2.2.260210.21290750.
- Update Teams to 1.0.0.2026043102.
- If you use Copilot on mobile, update Copilot for Android to 16.0.19815.10000 and Copilot for iOS to 2.107.2.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-26133 and every CVE in our database. Create a free account — no credit card required.
Create Free Account