
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26133 is an AI command injection vulnerability in Microsoft 365 Copilot and a broad set of related Microsoft mobile and desktop applications that allows an unauthorized network attacker to disclose sensitive information. Disclosed on March 12, 2026, as part of Microsoft's March 2026 Patch Tuesday release, the vulnerability affects Microsoft 365 Copilot (iOS and Android), Microsoft Teams (iOS and Android), Edge (iOS and Android), Outlook (iOS, Android, and macOS), Word, Excel, PowerPoint, OneNote, Power BI, and Loop across iOS and Android platforms. It carries a CVSS v3.1 base score of 7.1 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — 'Command Injection'), specifically in the context of AI-driven features within M365 Copilot. An attacker can craft malicious content — such as a specially formatted email or document — that, when processed or summarized by Copilot's AI engine, injects commands into the AI pipeline, causing it to disclose sensitive information to the attacker over the network. Exploitation requires user interaction (e.g., a user opening or having Copilot summarize a malicious email or Teams message), but no privileges are required on the attacker's side. The attack vector is network-based with low complexity, making it accessible to a wide range of threat actors (Microsoft MSRC, UndercodeTesting).
Successful exploitation results primarily in unauthorized information disclosure with high confidentiality impact, and a low-level integrity impact; availability is not affected. An attacker could leverage Copilot's AI summarization features to exfiltrate sensitive data from emails, Teams conversations, documents, or other content accessible to the victim user. The breadth of affected applications — spanning productivity tools, communication platforms, and analytics apps across iOS and Android — significantly widens the potential attack surface across enterprise environments (Microsoft MSRC, The Daily Tech Feed).
Microsoft released patches as part of the March 2026 Patch Tuesday update (released March 10–12, 2026). Organizations should update all affected applications to the following minimum versions or later: Microsoft 365 Copilot for iOS (2.107.2), Microsoft 365 Copilot for Android (16.0.19815.10000), Microsoft Teams for iOS (8.3.1), Microsoft Teams for Android (1.0.0.2026043102), Microsoft Edge for iOS and Android (145.3800.99), Microsoft Outlook for iOS and Android (5.2605.0), Microsoft Word/Excel/PowerPoint for iOS (2.106.2), Microsoft Word/Excel/PowerPoint for Android (16.0.19822.20038), Microsoft OneNote for Android (16.0.19725.20142), Microsoft Loop for iOS (2.106), and Microsoft Power BI for Android (2.2.260210.21290750). As a precautionary measure, users should be educated to avoid using Copilot to summarize content from untrusted or unknown senders until patches are applied (Microsoft MSRC).
The vulnerability received moderate coverage in the security community following its March 2026 disclosure. Several security blogs and news outlets highlighted the phishing-enablement angle, noting that the AI command injection mechanism could be weaponized to conduct sophisticated phishing attacks via Copilot's summarization features (The Daily Tech Feed, UndercodeTesting). Computerworld covered it as part of the broader March Patch Tuesday roundup of 83 vulnerabilities (Computerworld). LinkedIn and Bluesky posts from security professionals drew attention to the risk of AI-assisted prompt injection as an emerging attack class. Gartner commentary around the same period highlighted broader Microsoft 365 Copilot security risks, reflecting growing industry concern about AI-integrated productivity tools as an attack surface (Winbuzzer).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."