CVE-2026-26133: Microsoft 365 Copilot

High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Affected products

  • Microsoft 365 Copilot: before 2.107.2 (fixed in 2.107.2); before 16.0.19815.10000 (fixed in 16.0.19815.10000)
  • Microsoft Edge: before 145.3800.99 (fixed in 145.3800.99)
  • Microsoft Excel: before 2.106.2 (fixed in 2.106.2); before 16.0.19822.20038 (fixed in 16.0.19822.20038)
  • Microsoft Loop: before 2.106 (fixed in 2.106)
  • Microsoft Onenote: before 16.0.19725.20142 (fixed in 16.0.19725.20142); affected versions not specified
  • Microsoft Outlook: before 5.2605.0 (fixed in 5.2605.0); affected versions not specified
  • Microsoft Power BI: before 2.2.260210.21290750 (fixed in 2.2.260210.21290750); affected versions not specified
  • Microsoft PowerPoint: before 2.106.2 (fixed in 2.106.2); before 16.0.19822.20038 (fixed in 16.0.19822.20038)
  • Microsoft Teams: before 1.0.0.2026043102 (fixed in 1.0.0.2026043102); before 8.3.1 (fixed in 8.3.1)
  • Microsoft Word: before 2.106.2 (fixed in 2.106.2); before 16.0.19822.20038 (fixed in 16.0.19822.20038)

Published 2026-03-16. Last modified 2026-06-17.