Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Three information disclosure flaws in Microsoft Copilot, Copilot Studio and M365 Copilot

Microsoft disclosed three CVEs affecting Copilot Studio, Copilot and M365 Copilot (CVE-2026-21520, CVE-2026-21521, CVE-2026-24307) that allow unauthorized or unauthenticated attackers to disclose sensitive information over a network. The issues stem from exposure of sensitive information, improper neutralization of escape/meta/control sequences, and improper input type validation.

Disclosed 22 January 2026 · Record updated 13 September 2026

Impact

Attackers could view or disclose sensitive information over a network; in the Copilot Studio case without authentication.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-21520
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-21521
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-24307