CVE-2026-24307
Microsoft · Published January 22, 2026
9.3
CVSS v3.1
CRITICALPatch availableGet patch
Description
M365 Copilot Information Disclosure Vulnerability. Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Affected Products
- Microsoft 365 Copilot
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C