CVE-2026-26133: Microsoft 365 Copilot
High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Affected products
- Microsoft 365 Copilot: before 2.107.2 (fixed in 2.107.2); before 16.0.19815.10000 (fixed in 16.0.19815.10000)
- Microsoft Edge: before 145.3800.99 (fixed in 145.3800.99)
- Microsoft Excel: before 2.106.2 (fixed in 2.106.2); before 16.0.19822.20038 (fixed in 16.0.19822.20038)
- Microsoft Loop: before 2.106 (fixed in 2.106)
- Microsoft Onenote: before 16.0.19725.20142 (fixed in 16.0.19725.20142); affected versions not specified
- Microsoft Outlook: before 5.2605.0 (fixed in 5.2605.0); affected versions not specified
- Microsoft Power BI: before 2.2.260210.21290750 (fixed in 2.2.260210.21290750); affected versions not specified
- Microsoft PowerPoint: before 2.106.2 (fixed in 2.106.2); before 16.0.19822.20038 (fixed in 16.0.19822.20038)
- Microsoft Teams: before 1.0.0.2026043102 (fixed in 1.0.0.2026043102); before 8.3.1 (fixed in 8.3.1)
- Microsoft Word: before 2.106.2 (fixed in 2.106.2); before 16.0.19822.20038 (fixed in 16.0.19822.20038)
Published 2026-03-16. Last modified 2026-06-17.