High severity8.8NVD Advisory· Published Aug 18, 2026· Updated Sep 10, 2026
CVE-2026-24301
CVE-2026-24301
Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
Affected products
1Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24301nvdVendor Advisory
News mentions
8- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Hacker News · Aug 24, 2026
- Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 StoriesCyber Security News · Aug 23, 2026
- Microsoft Patches Exploited Entra ID VulnerabilitySecurityWeek · Aug 21, 2026
- Microsoft: 25 Vulnerabilities Disclosed, Including Exploited Entra ID FlawVypr Intelligence · Aug 20, 2026
- Microsoft Copilot & Windows: Four Vulnerabilities Patched in August 2026 BatchVypr Intelligence · Aug 19, 2026
- Critical Microsoft Copilot CoSnitch Vulnerability Lets Attackers Steal Sensitive Data With One ClickCyber Security News · Aug 19, 2026
- 'CoSnitch' Attack Tricked Copilot Into Mapping Out ArchitectureDark Reading · Aug 18, 2026
- Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected AppsThe Hacker News · Aug 18, 2026