cbcvebase.
CVE-2026-26133
published 2026-03-16

CVE-2026-26133: AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

high7.1CVSS 3.1
AVNACLPRNUIRSUCHILAN
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Affected

55 ranges· showing 25
VendorProductVersion rangeFixed in
microsoft365_copilot< 2.107.22.107.2
microsoft365_copilot< 16.0.19815.1000016.0.19815.10000
microsoftedge< 145.3800.99145.3800.99
microsoftexcel< 2.106.22.106.2
microsoftexcel< 16.0.19822.2003816.0.19822.20038
microsoftloop< 2.1062.106
microsoftmicrosoft_365_copilot_for_android>= 1.0 < 16.0.19815.1000016.0.19815.10000
microsoftmicrosoft_365_copilot_for_ios>= 1.0 < 2.107.22.107.2
microsoftmicrosoft_edge_for_android>= 1.0.0 < 145.3800.99145.3800.99
microsoftmicrosoft_edge_for_ios>= 1.0.0.0 < 145.3800.99145.3800.99
microsoftmicrosoft_excel_for_android>= 16.0.0.0 < 16.0.19822.2003816.0.19822.20038
microsoftmicrosoft_excel_for_ios>= 1.0 < 2.106.260206172.106.26020617
microsoftmicrosoft_loop_for_ios>= 2.0.0 < 2.106.260206172.106.26020617
microsoftmicrosoft_onenote>= 1.0.0 < 2.106.260206172.106.26020617
microsoftmicrosoft_onenote_for_android>= 16.0.1 < 16.0.19725.2014216.0.19725.20142
microsoftmicrosoft_outlook_for_android>= 1.0 < 5.26055.2605
microsoftmicrosoft_outlook_for_ios>= 1.0.0 < 5.26055.2605
microsoftmicrosoft_outlook_for_mac>= 1.0.0 < 5.26055.2605
microsoftmicrosoft_powerbi_for_android>= 2.0.0 < 2.2.260210.212907502.2.260210.21290750
microsoftmicrosoft_powerbi_for_ios>= 1.0.0 < 1.2.260302.21939101.2.260302.2193910
microsoftmicrosoft_powerpoint_for_android>= 16.0.0.0 < 16.0.19822.2003816.0.19822.20038
microsoftmicrosoft_powerpoint_for_ios>= 1.0 < 2.106.260206172.106.26020617
microsoftmicrosoft_teams_for_android>= 1.0.0 < 1.0.0.20260431021.0.0.2026043102
microsoftmicrosoft_teams_for_ios>= 2.0.0 < 8.3.18.3.1
microsoftmicrosoft_word_for_android>= 16.0.0.0 < 16.0.19822.2003816.0.19822.20038