CyberICT

CVE-2026-24307

Microsoft · Published January 22, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

M365 Copilot Information Disclosure Vulnerability. Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Affected Products

  • Microsoft 365 Copilot

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C