Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Command injection flaws in Microsoft Copilot and M365 Copilot (CVE-2026-41090, CVE-2026-42827)

Two command injection vulnerabilities were published for Microsoft's Copilot assistants: CVE-2026-41090 lets an unauthorized attacker perform tampering over a network in Microsoft Copilot, and CVE-2026-42827 lets an unauthorized attacker disclose information over a network in M365 Copilot. Both stem from improper neutralization of special elements used in a command.

Disclosed 22 May 2026 · Record updated 13 September 2026

Impact

Unauthenticated network attackers could tamper with data (Microsoft Copilot) or disclose information (M365 Copilot).

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41090
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42827