Microsoft discloses multiple Copilot injection and access control CVEs (May 2026)
Microsoft published a set of CVEs in May 2026 affecting M365 Copilot, Copilot Chat in Microsoft Edge, GitHub Copilot with Visual Studio, and Azure AI Foundry M365 published agents. The flaws include command/output injection issues enabling information disclosure, tampering or security feature bypass over a network, and improper access control allowing privilege elevation or local spoofing.
Disclosed 7 May 2026 · Record updated 13 September 2026
Impact
Unauthorized attackers could disclose information or tamper with data over a network, bypass a security feature, elevate privileges, or perform local spoofing via Microsoft Copilot products.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26129
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26164
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33111
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-35435
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41100
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41109
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41614
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42893
