CVE-2026-26133
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-26133 is an AI command injection vulnerability in Microsoft 365 Copilot and a broad set of related Microsoft mobile and desktop applications that allows an unauthorized network attacker to disclose sensitive information. Disclosed on March 12, 2026, as part of Microsoft's March 2026 Patch Tuesday release, the vulnerability affects Microsoft 365 Copilot (iOS and Android), Microsoft Teams (iOS and Android), Edge (iOS and Android), Outlook (iOS, Android, and macOS), Word, Excel, PowerPoint, OneNote, Power BI, and Loop across iOS and Android platforms. It carries a CVSS v3.1 base score of 7.1 (High) (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — 'Command Injection'), specifically in the context of AI-driven features within M365 Copilot. An attacker can craft malicious content — such as a specially formatted email or document — that, when processed or summarized by Copilot's AI engine, injects commands into the AI pipeline, causing it to disclose sensitive information to the attacker over the network. Exploitation requires user interaction (e.g., a user opening or having Copilot summarize a malicious email or Teams message), but no privileges are required on the attacker's side. The attack vector is network-based with low complexity, making it accessible to a wide range of threat actors (Microsoft MSRC, UndercodeTesting).

Impact

Successful exploitation results primarily in unauthorized information disclosure with high confidentiality impact, and a low-level integrity impact; availability is not affected. An attacker could leverage Copilot's AI summarization features to exfiltrate sensitive data from emails, Teams conversations, documents, or other content accessible to the victim user. The breadth of affected applications — spanning productivity tools, communication platforms, and analytics apps across iOS and Android — significantly widens the potential attack surface across enterprise environments (Microsoft MSRC, The Daily Tech Feed).

Exploitation steps

  1. Craft malicious content: The attacker prepares a specially crafted email, Teams message, or document embedding hidden AI prompt injection payloads designed to manipulate Copilot's summarization or command processing behavior.
  2. Deliver to target: The attacker sends the malicious email or message to a victim who uses Microsoft 365 Copilot on an affected application version (e.g., Outlook for iOS before 5.2605.0, Teams for iOS before 8.3.1).
  3. Trigger Copilot processing: The victim opens the message or document and uses Copilot to summarize or process it — or Copilot automatically processes it — causing the injected AI commands to be evaluated by the Copilot AI engine.
  4. Exfiltrate sensitive data: The injected commands instruct Copilot to retrieve and disclose sensitive information (e.g., contents of other emails, calendar entries, or documents accessible to the victim) and return it in a manner observable by the attacker, such as through a crafted response or external callback. (UndercodeTesting, The Daily Tech Feed)

Indicators of compromise

  • Network: Unexpected outbound connections from Microsoft 365 mobile apps to unfamiliar external endpoints following Copilot summarization activity; anomalous data exfiltration patterns in network logs correlated with Copilot usage.
  • Logs: Microsoft 365 audit logs showing Copilot activity (e.g., summarization requests) triggered on emails or messages originating from external or unknown senders; unusual Copilot query patterns accessing multiple mailbox items in rapid succession.
  • User Behavior: Users reporting unexpected or anomalous Copilot responses that reference content from unrelated emails or documents; Copilot outputs containing data the user did not explicitly request.
  • Email/Message Artifacts: Inbound emails or Teams messages containing unusual formatting, hidden text, or encoded strings that may represent embedded prompt injection payloads.

Mitigation and workarounds

Microsoft released patches as part of the March 2026 Patch Tuesday update (released March 10–12, 2026). Organizations should update all affected applications to the following minimum versions or later: Microsoft 365 Copilot for iOS (2.107.2), Microsoft 365 Copilot for Android (16.0.19815.10000), Microsoft Teams for iOS (8.3.1), Microsoft Teams for Android (1.0.0.2026043102), Microsoft Edge for iOS and Android (145.3800.99), Microsoft Outlook for iOS and Android (5.2605.0), Microsoft Word/Excel/PowerPoint for iOS (2.106.2), Microsoft Word/Excel/PowerPoint for Android (16.0.19822.20038), Microsoft OneNote for Android (16.0.19725.20142), Microsoft Loop for iOS (2.106), and Microsoft Power BI for Android (2.2.260210.21290750). As a precautionary measure, users should be educated to avoid using Copilot to summarize content from untrusted or unknown senders until patches are applied (Microsoft MSRC).

Community reactions

The vulnerability received moderate coverage in the security community following its March 2026 disclosure. Several security blogs and news outlets highlighted the phishing-enablement angle, noting that the AI command injection mechanism could be weaponized to conduct sophisticated phishing attacks via Copilot's summarization features (The Daily Tech Feed, UndercodeTesting). Computerworld covered it as part of the broader March Patch Tuesday roundup of 83 vulnerabilities (Computerworld). LinkedIn and Bluesky posts from security professionals drew attention to the risk of AI-assisted prompt injection as an emerging attack class. Gartner commentary around the same period highlighted broader Microsoft 365 Copilot security risks, reflecting growing industry concern about AI-integrated productivity tools as an attack surface (Winbuzzer).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16412CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026
CVE-2026-16411CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NoYesJul 21, 2026
CVE-2026-16410CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NoYesJul 21, 2026
CVE-2026-16408CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026
CVE-2026-16409HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management