Microsoft Copilot & Windows: Four Vulnerabilities Patched in August 2026 Batch
Microsoft patched four vulnerabilities from August 17-19, 2026, including a high-severity command injection flaw in Copilot (CVE-2026-24301) that enables data exfiltration.

Key findings
- Microsoft patched four vulnerabilities between August 17-19, 2026, including a critical command injection flaw in Copilot.
- CVE-2026-24301, nicknamed 'CoSnitch', allows data exfiltration from connected apps via a single click.
- The CoSnitch vulnerability was discovered by Varonis Threat Labs and reported in December 2025.
- Other vulnerabilities include a Remote Desktop Client information disclosure and a Windows Telephony Service race condition.
- A Kiota code generator vulnerability (CVE-2026-73851) allows file tampering via OpenAPI descriptions.
On August 19, 2026, Microsoft addressed a batch of four vulnerabilities disclosed over a two-day period, spanning August 17th to August 19th. The most severe of these, CVE-2026-24301, is a high-severity command injection flaw in Microsoft Copilot that could allow an attacker to disclose information over a network. This vulnerability, nicknamed "CoSnitch" by researchers, was patched by Microsoft on August 18, 2026.
The CoSnitch vulnerability (CVE-2026-24301) was discovered by Varonis Threat Labs and allows an attacker to exfiltrate sensitive data from a victim's connected accounts with a single click on a malicious link. Researchers noted that this flaw, along with two others they previously discovered (Reprompt and SearchLeak), highlight potential security weaknesses in Copilot's ability to process user inputs and maintain safety guardrails. Varonis initially reported CoSnitch to Microsoft in December 2025.
In addition to the Copilot vulnerability, Microsoft also released patches for two medium-severity vulnerabilities and one high-severity flaw:
- **CVE-2026-69550**: An out-of-bounds read vulnerability in the Remote Desktop Client, rated Medium (CVSSv3 6.5), which could lead to information disclosure over a network.
- **CVE-2026-62727**: A high-severity (CVSSv3 7.0) race condition vulnerability in the Windows Telephony Service. This flaw could allow a local, authenticated attacker to elevate their privileges.
- **CVE-2026-73851**: A Medium severity vulnerability in Kiota, an OpenAPI-based HTTP Client code generator. This flaw could allow an attacker to tamper with OpenAPI descriptions to reference files outside the intended package, potentially leading to unauthorized access or disclosure. This issue affects versions prior to 1.29.1 and 1.34.0.
The coordinated disclosure of these vulnerabilities underscores the importance of timely patching and security updates for Microsoft products. Users are advised to ensure their systems are updated to the latest versions to mitigate these risks. The focus on Copilot vulnerabilities, particularly CVE-2026-24301, highlights the evolving threat landscape surrounding AI-powered tools and the potential for sophisticated prompt injection and data exfiltration attacks.
The patches for CVE-2026-24301 were released on August 18, 2026, while the other vulnerabilities were addressed in Microsoft's security updates around August 19, 2026. Users should consult Microsoft's Security Update Guide for specific version information and detailed remediation steps. The batch of disclosures, clustered around August 17-19, 2026, emphasizes the ongoing need for vigilance in securing complex software ecosystems.