NY15:59
    LDN20:59
    HKG03:59
    TYO04:59
    Gold4,498-0.71%
    Bitcoin75,793-2.37%
    Gold4,498-0.7%
    Bitcoin75,793-2.4%
    LATEST NEWS
    Why is the US putting pressure on Cuba and what are Trump's aims?40 minutesMusk Dominates SpaceX Ownership Ahead of IPOabout 1 hourQatar Mediates USabout 1 hourTrump Administration Moves to Force Most Green-Card Applicants Overseasabout 1 hourWarsh Takes Fed Chair Role Amid Independence Pledgeabout 1 hourGabbard’s Exit Exposes Divisions Inside Trump’s Security Apparatusabout 1 hourGiants’ Roy Robertson-Harris tears Achilles at OTAs, out for 2026 seasonabout 2 hoursIndia Swelters Under Extreme Heatwaveabout 2 hoursCongo Ebola Outbreak: WHO Raises Global Alertabout 2 hoursVyshyvanka Day: Ukraine's Embroidered Soul Shinesabout 2 hoursImmigration Agency Curbs Green Card Pathabout 2 hoursChina Restricts Cross-Border Data Flowabout 2 hoursStellantis Eyes North American Production for Chinese Carsabout 2 hoursWorldwide Fury Erupts Over Detainee Abuseabout 2 hoursOxford Scientists Unveil Novel Ebola Vaccineabout 2 hoursWhy is the US putting pressure on Cuba and what are Trump's aims?40 minutesMusk Dominates SpaceX Ownership Ahead of IPOabout 1 hourQatar Mediates USabout 1 hourTrump Administration Moves to Force Most Green-Card Applicants Overseasabout 1 hourWarsh Takes Fed Chair Role Amid Independence Pledgeabout 1 hourGabbard’s Exit Exposes Divisions Inside Trump’s Security Apparatusabout 1 hourGiants’ Roy Robertson-Harris tears Achilles at OTAs, out for 2026 seasonabout 2 hoursIndia Swelters Under Extreme Heatwaveabout 2 hoursCongo Ebola Outbreak: WHO Raises Global Alertabout 2 hoursVyshyvanka Day: Ukraine's Embroidered Soul Shinesabout 2 hoursImmigration Agency Curbs Green Card Pathabout 2 hoursChina Restricts Cross-Border Data Flowabout 2 hoursStellantis Eyes North American Production for Chinese Carsabout 2 hoursWorldwide Fury Erupts Over Detainee Abuseabout 2 hoursOxford Scientists Unveil Novel Ebola Vaccineabout 2 hours
    Technology

    Microsoft patches three critical information-disclosure flaws in Copilot

    Microsoft has patched three critical information disclosure vulnerabilities in Microsoft 365 Copilot and Copilot Chat, preventing sensitive data exposure.

    Published10 May 2026, 13:04:53
    Microsoft patches three critical information-disclosure flaws in Copilot
    A360
    Key Takeaways✦ Atlas AI
    01

    Three critical vulnerabilities patched.

    02

    No user action required for mitigation.

    03

    Sensitive information disclosure prevented.

    Atlas AI

    Atlas AI

    Micrososources disclosed and said it has fully remediated three critical information-disclosure vulnerabilities that affected Micrososources 365 Copilot and Copilot Chat embedded in Micrososources Edge. Patches and mitigations were released and completed on May 7, 2026, and Micrososources said no action was required from end users or administrators. The company published advisories through its Security Response Center as part of its cloud CVE transparency initiative.

    Two of the flaws, tracked as CVE-2026-26129 and CVE-2026-26164, target Micrososources 365 Copilot’s Business Chat. Micrososources describes these issues as stemming from improper neutralization of special elements in output used by downstream components, an injection-style failure classified under CWE-74. The vendor said the attack vector is network-based, requires no privileges or user interaction, and carries a high confidentiality impact.

    The third flaw, CVE-2026-33111, affects Copilot Chat when embedded in Micrososources Edge and is classified under CWE-77, an improper neutralization of special elements used in a command (command injection). Micrososources lists all three vulnerabilities under the Information Disclosure impact category and assigns each a Critical severity rating. For CVE-2026-26164 Micrososources notes the exploitability assessment as “Exploitation Less Likely” and lists exploit code maturity as unproven.

    Network-based, no-interaction information-disclosure flaws can expose sensitive organizational data, raising the risk for enterprises that integrate Copilot with internal systems and grant it access to corporate information.

    Such vulnerabilities can allow attackers to retrieve confidential data from cloud services without user interaction, increasing exposure for businesses that rely on Copilot integrations.

    - Three CVEs disclosed and remediated: CVE-2026-26129, CVE-2026-26164, CVE-2026-33111. - Patches and mitigations were released and completed by Micrososources on May 7, 2026. - CVE-2026-26129 and CVE-2026-26164 affect Micrososources 365 Copilot Business Chat. ” - CVE-2026-33111 affects Copilot Chat embedded in Micrososources Edge and is classified under CWE-77 (command injection). - All three are classified as Critical and as Information Disclosure issues.

    Enterprises should review Micrososources Security Response Center advisories for follow-up guidance and monitor Copilot and Edge logs for related anomalous activity.

    Share

    Related Articles

    Atlas360

    Sign up for Atlas Daily

    The daily global news briefing you can trust.

    every weekday·Read it now

    or
    Sign in

    Already subscribed? Sign in and we won't show you this message again.