Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Injection flaws in Microsoft Copilot products allow info disclosure and code execution

Three CVEs published for Microsoft Copilot products describe improper neutralization of special elements ('injection') issues: CVE-2026-42824 and CVE-2026-47644 allow unauthorized attackers to disclose information over a network in M365 Copilot and Copilot Chat (Microsoft Edge), while CVE-2026-45497 allows an authorized attacker to execute code over a network in Microsoft Copilot.

Disclosed 4 June 2026 · Record updated 13 September 2026

Impact

Network-based information disclosure in M365 Copilot and Copilot Chat in Microsoft Edge, and remote code execution in Microsoft Copilot by an authorized attacker.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42824
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-45497
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-47644