Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-21521 Word Copilot Information Disclosure Vulnerability
Published January 23, 2026
Published January 23, 2026
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.