Medium severity6.5NVD Advisory· Published Jun 4, 2026· Updated Jun 8, 2026
CVE-2026-42824
CVE-2026-42824
Description
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Affected products
1Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42824nvdVendor Advisory
News mentions
9- Critical Vulnerability in GCP Dialogflow Allows Attackers to Inject Malicious CodeCyber Security News · Jul 7, 2026
- 22nd June – Threat Intelligence ReportCheck Point Research · Jul 1, 2026
- Copilot 'SearchLeak' Attack Allows 1-Click Data TheftDark Reading · Jun 15, 2026
- One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA CodesThe Hacker News · Jun 15, 2026
- Critical Microsoft 365 Copilot Vulnerability Allows Attackers to Steal Data in One ClickCyber Security News · Jun 15, 2026
- New attack turned Microsoft 365 Copilot into 1-click data theft toolBleepingComputer · Jun 15, 2026
- Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilitiesCisco Talos Intelligence · Jun 9, 2026
- Microsoft: Seven Critical and High Vulnerabilities Disclosed on June 4thVypr Intelligence · Jun 4, 2026
- June 2026 Patch Tuesday: Microsoft Patches 206 Vulnerabilities Including Three Publicly Disclosed Zero-DaysCrowdStrike Blog