IT

Tracker / CVE-2026-26133

CVE-2026-26133

High 7.1

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Affected products and versions

microsoft 365_copilot · … → 16.0.19815.10000
microsoft 365_copilot · … → 2.107.2
microsoft edge · … → 145.3800.99
microsoft excel · … → 16.0.19822.20038
microsoft excel · … → 2.106.2
microsoft loop · … → 2.106
microsoft onenote
microsoft onenote · … → 16.0.19725.20142
microsoft outlook
microsoft outlook · … → 5.2605.0
microsoft power_bi
microsoft power_bi · … → 2.2.260210.21290750
microsoft powerpoint · … → 16.0.19822.20038
microsoft powerpoint · … → 2.106.2
microsoft teams · … → 1.0.0.2026043102
microsoft teams · … → 8.3.1
microsoft word · … → 16.0.19822.20038
microsoft word · … → 2.106.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References