Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-33102: Open redirect in Microsoft 365 Copilot enables privilege elevation

A URL redirection to untrusted site ('open redirect') vulnerability in Microsoft 365 Copilot allows an unauthorized attacker to elevate privileges over a network. The issue is tracked as CVE-2026-33102 and documented in Microsoft's MSRC update guide.

Disclosed 23 April 2026 · Record updated 13 September 2026

Impact

An unauthorized remote attacker could elevate privileges via an open redirect in M365 Copilot.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33102