Critical SearchLeak Vulnerability in Microsoft 365 Copilot Exposes Sensitive Data

Critical SearchLeak Vulnerability in Microsoft 365 Copilot Exposes Sensitive Data

First seen 15 Jun 2026, 15:33 UTC BleepingcomputerCybersecuritynewsThehackernewsLetsdatascienceThenextweb+24 86% similarity 70.5

Article Content

Browse articles
ThreatCluster

A newly disclosed vulnerability in Microsoft 365 Copilot Enterprise, named SearchLeak (CVE-2026-42824), allows attackers to exfiltrate sensitive data with a single click on a crafted link. Discovered by Varonis Threat Labs, the attack exploits a chain of three vulnerabilities: parameter-to-prompt injection, an HTML rendering race condition, and a server-side request forgery (SSRF) via Bing. The attack targets emails, calendar entries, and files stored in OneDrive and SharePoint, enabling the theft of sensitive information such as MFA codes and access tokens. Microsoft rated the vulnerability as critical and patched it on June 4, 2026, requiring no action from users. The flaw is particularly dangerous as it bypasses traditional security measures due to the use of a legitimate Microsoft domain. No evidence of in-the-wild exploitation has been reported.

Key Points: • SearchLeak allows one-click data exfiltration from Microsoft 365 Copilot Enterprise. • The attack exploits three vulnerabilities, including parameter-to-prompt injection and SSRF. • Microsoft has patched the vulnerability, but users should remain vigilant against suspicious links.

ThreatCluster AI How this analysis works

Timeline

2025-06-11
CVE-2025-32711 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-42824 published
Microsoft disclosed the SearchLeak vulnerability, assigning it a critical severity rating.
Thenextweb
2026-06-15
SearchLeak vulnerability disclosed by Varonis
Varonis Threat Labs detailed the three-stage attack chain that enables data theft through Microsoft 365 Copilot.
Darkreading
2026-06-16
SearchLeak vulnerability reported in multiple outlets
Various cybersecurity news outlets reported on the SearchLeak vulnerability and its implications for enterprise security.
Thecyberexpress

Community

Browse all →