Bleepingcomputer Critical SearchLeak Vulnerability in Microsoft 365 Copilot Exposes Sensitive Data
Article Content
- •SearchLeak allows one-click data exfiltration from Microsoft 365 Copilot Enterprise.
- •The attack exploits three vulnerabilities, including parameter-to-prompt injection and SSRF.
- •Microsoft has patched the vulnerability, but users should remain vigilant against suspicious links.
A newly disclosed vulnerability in Microsoft 365 Copilot Enterprise, named SearchLeak (CVE-2026-42824), allows attackers to exfiltrate sensitive data with a single click on a crafted link. Discovered by Varonis Threat Labs, the attack exploits a chain of three vulnerabilities: parameter-to-prompt injection, an HTML rendering race condition, and a server-side request forgery (SSRF) via Bing. The attack targets emails, calendar entries, and files stored in OneDrive and SharePoint, enabling the theft of sensitive information such as MFA codes and access tokens. Microsoft rated the vulnerability as critical and patched it on June 4, 2026, requiring no action from users. The flaw is particularly dangerous as it bypasses traditional security measures due to the use of a legitimate Microsoft domain. No evidence of in-the-wild exploitation has been reported.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (34)
Following this threat?
Track Aim Security and CVE-2025-32711 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Emerging Threats from AI-Generated Content Exfiltration A new tool called `exfil-scan` has been developed to detect data exfiltration signals in outputs from large language models (LLMs) and AI-generated content. This tool addresses vulnerabilities highlighted by the EchoLeak attack family, particularly CVE-2025-32711, which demonstrated how hidden payloads could be…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…