Skip to main content
Father's Day Sale — Get 40% off Vantage for yourself or as a gift
Published loading...Updated

Critical Copilot Vulnerability Allowed Hackers to Seal 2FA Code From Users

Varonis said the chained flaw could expose email content, calendar details and access codes before Microsoft fixed CVE-2026-42824.

  • Varonis researchers discovered SearchLeak, a critical vulnerability in Microsoft Copilot Enterprise Search, which Microsoft patched on Tuesday as CVE-2026-42824 with a maximum severity rating.
  • The three-stage attack chain combines a Parameter-to-Prompt Injection, an HTML rendering race condition, and a CSP bypass enabled by Bing server-side request forgery, allowing attackers to bypass security protections.
  • "The victim doesn't type anything. They click a link, and Copilot takes care of the rest," Varonis researchers explained, describing how attackers craft malicious links to exfiltrate emails and documents.
  • Microsoft has already fixed the vulnerabilities that SearchLeak exploited, meaning users require no action to mitigate this threat.
  • SearchLeak targeted Copilot Enterprise Search, potentially exposing sensitive corporate data including emails, meeting notes, SharePoint documents, and OneDrive files accessible within organizations.
Insights by Ground AI

14 Articles

Varonis security researchers have found a new route of attack to easily read confidential data from business environments via Microsoft 365 Copilot.

Read Full Article

The failure in Microsoft 365 Copilot re-emphasized the security risks in corporate artificial intelligence tools, especially when integrated into complex cloud ecosystems. Researchers at Varonis Threat Labs revealed a critical vulnerability that allowed data theft with just one click, without the need for additional credentials or sophisticated exploration by the attacker. The problem, named SearchLeak and categorized as CVE-2026-42824, exposed …

Read Full Article

By treating a request as an instruction to execute, Microsoft 365 Copilot could again be hijacked to search for internal content without permission, then rely on Bing to extract the recovered data.

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe
Father's Day SaleGet 40% off Vantage subscriptions for yourself or a friend.Get Started

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in New York, United States on Monday, June 15, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal