Multiple vulnerabilities in Microsoft Copilot products
Two vulnerabilities were disclosed in Microsoft's Copilot products: a race condition in Copilot Chat allowing information disclosure, and improper cryptographic signature verification in Copilot Studio allowing privilege escalation.
Disclosed 28 August 2026 · Record updated 13 September 2026
Impact
Race condition in Copilot Chat allows information disclosure to authorized attackers; improper signature verification in Copilot Studio allows unauthorized privilege escalation.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-58616
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-80098
- github.comhttps://github.com/advisories/GHSA-r9hf-26xj-x88v
