CVE-2026-26164

Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

high 7.5 CVSS 3.1
Published: May 7, 2026
Modified: May 8, 2026
Vendor: Microsoft
Product: 365 Copilot Chat