๐Ÿ” CVE Alert

CVE-2026-26133

HIGH 7.1

M365 Copilot Information Disclosure Vulnerability

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Vendor microsoft
Product microsoft 365 copilot for android
Ecosystems
Industries
TechnologyEnterprise
Published Mar 13, 2026
Last Updated Apr 14, 2026
Stay Ahead of the Next One

Get instant alerts for microsoft microsoft 365 copilot for android

Be the first to know when new high vulnerabilities affecting microsoft microsoft 365 copilot for android are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Microsoft / Microsoft 365 Copilot for Android
1.0 < 16.0.19815.10000
Microsoft / Microsoft 365 Copilot for iOS
1.0 < 2.107.2
Microsoft / Microsoft Edge for Android
1.0.0 < 145.3800.99
Microsoft / Microsoft Edge for iOS
1.0.0.0 < 145.3800.99
Microsoft / Microsoft Excel for Android
16.0.0.0 < 16.0.19822.20038
Microsoft / Microsoft Excel for iOS
1.0 < 2.106.26020617
Microsoft / Microsoft Loop for iOS
2.0.0 < 2.106.26020617
Microsoft / Microsoft OneNote
1.0.0 < 2.106.26020617
Microsoft / Microsoft OneNote for Android
16.0.1 < 16.0.19725.20142
Microsoft / Microsoft Outlook for Android
1.0 < 5.2605
Microsoft / Microsoft Outlook for iOS
1.0.0 < 5.2605
Microsoft / Microsoft Outlook for Mac
1.0.0 < 5.2605
Microsoft / Microsoft PowerBI for Android
2.0.0 < 2.2.260210.21290750
Microsoft / Microsoft PowerBI for iOS
1.0.0 < 1.2.260302.2193910
Microsoft / Microsoft PowerPoint for Android
16.0.0.0 < 16.0.19822.20038
Microsoft / Microsoft PowerPoint for iOS
1.0 < 2.106.26020617
Microsoft / Microsoft Teams for Android
1.0.0 < 1.0.0.2026043102
Microsoft / Microsoft Teams for iOS
2.0.0 < 8.3.1
Microsoft / Microsoft Word for Android
16.0.0.0 < 16.0.19822.20038
Microsoft / Microsoft Word for iOS
2.0.0 < 2.106.26020617

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
msrc.microsoft.com: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26133