Saturday , October 3 2026
Microsoft 365 Copilot

3 Critical Microsoft 365 Copilot flaws Expose sensitive Information

Microsoft fixed 3 critical security issues in Microsoft 365 Copilot and Copilot Chat in Microsoft Edge. These were released on May 7, 2026, and users or admins don’t need to do anything.

Microsoft’s Security Response Center shared updates on CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111 to show their ongoing promise of openness in their cloud services.

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Microsoft has fixed all three issues completely, following its cloud CVE transparency plan in the “Toward Greater Transparency: Unveiling Cloud Service CVEs” program.

Microsoft 365 Copilot Vulnerabilities

CVE-2026-26129 impacts Microsoft 365 Copilot’s Business Chat. The problem comes from not properly handling special characters in the output, which could let an attacker reveal sensitive information on a network.

CVE-2026-26164 affects M365 Copilot and falls under CWE-74 (Bad Handling of Special Elements in Output Used by Another Part — Injection).

The attack comes from the network, does not need special access or user actions, and has a big effect on confidentiality. The chance of it being exploited is rated as “Exploitation Less Likely,” and the readiness of the exploit code is marked as untested.

CVE-2026-33111 impacts Copilot Chat in Microsoft Edge and is categorized as CWE-77 (Improper Control of Special Elements in a Command — Command Injection).

It has the same CVSS score of 7.5 / 6.5 (temporal) as CVE-2026-26164. It also has the same attack type: it can be accessed through a network, does not need special permissions, does not require user actions, and has a big impact on confidentiality.

Microsoft thanked Estevam Arantes of Microsoft for finding both CVE-2026-26129 and CVE-2026-26164. They also gave credit to independent researcher 0xSombra for CVE-2026-26164.

Microsoft has put fixes in place at the service level. Companies do not have to install updates or change settings.

Security teams should check Copilot’s data access permissions and apply least-privilege rules to lower the risk of similar problems in the future.

Check Also

CISA

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw …