Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Command injection flaws in Microsoft Copilot and M365 Copilot allow information disclosure

Two CVEs (CVE-2026-24299 and CVE-2026-26136) describe improper neutralization of special elements used in a command in M365 Copilot and Microsoft Copilot, allowing an unauthorized attacker to disclose information over a network. Microsoft published advisories for both issues via MSRC.

Disclosed 19 March 2026 · Record updated 13 September 2026

Impact

An unauthorized attacker could disclose information over a network by exploiting command injection in Copilot.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-24299
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26136