Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Command Injection and SSRF Vulnerabilities in Microsoft Copilot

Two vulnerabilities were identified in Microsoft Copilot: a command injection flaw (CVE-2026-24301) allowing unauthorized attackers to disclose information, and an SSRF vulnerability (CVE-2026-69855) in Azure allowing authorized attackers to access sensitive data over a network.

Disclosed 18 August 2026 · Record updated 13 September 2026

Impact

Information disclosure via command injection and server-side request forgery attacks against Microsoft Copilot and its Azure deployment.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-24301
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-69855