CVE-2026-42824
CVSS 6.5 MEDIUM: improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an… EPSS 8% (94th percentile), up from 0.5%.
AI Security · AI-Powered Attack
A real microsoft.com search link can carry instructions, not just a query, so the usual trust checks miss the attack before Copilot starts reading internal data. In SearchLeak, the user only clicks once; the link’s q parameter is treated like a prompt, and Copilot can be steered toward mailbox or file content that the user never typed out.
Varonis published a proof of concept for CVE-2026-42824, and Microsoft says it already applied backend mitigation. The chain affects Microsoft 365 Copilot Enterprise and Microsoft Copilot Enterprise Search, with exposed data including emails, calendar items, OneDrive files, SharePoint documents, and secrets such as MFA codes and passwords.
The risk is broader than one bug class. Any AI assistant that accepts instructions through links or prompts and can reach internal content inherits the same trust problem, even when the destination domain is legitimate.
5 sources · Jun 19
CVSS 6.5 MEDIUM: improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an… EPSS 8% (94th percentile), up from 0.5%.
CSO Online
M365 Copilot SearchLeak: Your prompt injection attack surface just got bigger
Although not the first of its kind, researchers’ POC attack against Microsoft’s M365 Copilot Enterprise underscores parameter-to-prompt (P2P) injections as a potentially broad threat.
originalArs Technica Security
Critical Copilot vulnerability allowed hackers to steal 2FA code from users
SearchLeak exploit shows why the industry's approach to LLM security fails over and over.
originalThe Hacker News
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Microsoft fixed a critical Copilot Enterprise Search flaw that could expose emails, calendars, and indexed files through one trusted link.
originalPart of the PlainSec briefing for 2026-06-15
Every edition of this story: Trusted Microsoft Links Can Smuggle Copilot Prompts