CVE-2026-24307 M365 Copilot Information Disclosure Vulnerability
Published January 23, 2026
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Published January 23, 2026
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Published January 23, 2026
Improper limitation of a pathname to a restricted directory (‘path traversal’) in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
Published January 23, 2026
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated FAQ information. This is an informational change only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 16, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
Published January 16, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.