CVE-2026-69855: Microsoft Copilot SSRF Vulnerability Disclosed

CVE-2026-69855: Microsoft Copilot SSRF Vulnerability Disclosed

First seen 22 Aug 2026, 00:48 UTC Feedlycvefeed.ioportal.msrc.microsoft.comvulners.comvuldb.com 94% similarity 60.0

Article Content

Browse articles
ThreatCluster

A server-side request forgery (SSRF) vulnerability, identified as CVE-2026-69855, has been discovered in Microsoft Copilot in Azure. This flaw allows authorized attackers to disclose sensitive information over a network. The vulnerability has been rated with a severity score of 7.7, classified as high. Affected systems include various versions of Microsoft Copilot in Azure, although specific versions were not detailed in the reports. The vulnerability was published on August 20, 2026, and has been acknowledged by multiple cybersecurity sources. Current advisories recommend monitoring for potential exploits and applying necessary mitigations. No active exploits have been reported yet, but the potential for information disclosure poses a significant risk.

Key Points: • CVE-2026-69855 is a high-severity SSRF vulnerability in Microsoft Copilot in Azure. • The vulnerability allows authorized attackers to disclose sensitive information over a network. • As of now, no active exploits have been reported, but vigilance is advised.

ThreatCluster AI How this analysis works

Timeline

2026-08-20
CVE-2026-69855 published
Microsoft disclosed the SSRF vulnerability in Copilot, allowing information disclosure by authorized attackers.
cvefeed.io
2026-08-21
First mentions of CVE-2026-69855
Feedly reported on the vulnerability, detailing its attack vector and severity score.
Feedly
Recent
Advisories issued
Cybersecurity advisories recommend monitoring for potential exploits related to CVE-2026-69855.
Date unknown

Community

Browse all →

Tracked Entities in This Story