Skip to content
Microsoft patches SearchLeak vulnerability in Copilot for Microsoft 365

Microsoft patches SearchLeak vulnerability in Copilot for Microsoft 365

Feeds.4Sysops IT News June 16, 2026

Microsoft has addressed a critical vulnerability chain in Copilot for Microsoft 365 that allowed for unauthorized data exfiltration. The flaw, identified as CVE-2026-42824 and dubbed SearchLeak, enabled attackers to steal sensitive information from a user's mailbox, OneDrive, and SharePoint. Because the fix was implemented on the backend, organizations do not need to take any manual action to protect their environments. Source

Extracted Entities