CVE-2026-26133: Cross-Prompt Injection in Microsoft Copilot Email/Teams Summarization Enables AI-Mediated Phishing
CVE-2026-26133 (TL-2026-1538), also tracked as Copilot Cross-Prompt Injection, is a high-severity software vulnerability scored CVSS 7.1, first published 2026-03-12 and last reviewed 2026-09-09. It has no confirmed attribution, affects Microsoft Microsoft 365 Copilot (Outlook Summarize / Copilot pane, references 1 CVE (CVE-2026-26133), maps to 26 MITRE ATT&CK / ATLAS techniques (AML.T0048.003, AML.T0051.001, AML.T0052), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-1538
- Threat ID
- TL-2026-1538
- Also known as
- Copilot Cross-Prompt Injection, CO-PILOT DISENGAGE AUTOPHISH, Copilot AI-Mediated Phishing
- Severity
- HIGH
- CVSS
- 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-03-12
- Last reviewed
- 2026-09-09
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- all sectors using microsoft 365 copilot, enterprise, government administration, finance, health, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 30
- Updates
- 2026-09-09 · revalidated 1× · latest source
Malware and tooling in CVE-2026-26133
Malware and tooling: Microsoft 365 Copilot, Outlook Copilot Summarize / Copilot pane, Teams Copilot summarization
A cross-prompt injection (XPIA) flaw in Microsoft 365 Copilot's email and Teams summarization surfaces let attackers embed HTML/CSS-hidden instructions in ordinary emails that the underlying LLM ingests but the human recipient never sees, hijacking Copilot's trusted summary UI to present fake security alerts and phishing links as system-generated content. Disclosed by Permiso Security researcher Andi Ahmeti; Microsoft assigned CVSS 7.1 (CVE-2026-26133) and completed a phased patch rollout by March 11, 2026.
How CVE-2026-26133 works
CVE-2026-26133 is an AI command injection / information disclosure vulnerability (CWE-77) in Microsoft 365 Copilot's summarization pipeline. The attack requires no attachment, macro, or traditional exploit code: an attacker only needs to land an ordinary email in the victim's inbox. Using HTML/CSS rendering tricks (e.g., zero-size fonts, off-screen positioning, matching foreground/background colors, or comment-like markup), the attacker embeds instruction-like text within the raw message body. This text is invisible to the human reader in the Outlook reading pane but is fully present in the raw content that Copilot's underlying model ingests when a user clicks "Summarize" in Outlook, opens the Outlook Copilot chat pane, or has the email surfaced through Teams Copilot. Because Copilot does not sufficiently separate trusted system instructions from untrusted email content (insufficient input validation/sanitization per CWE-77), the hidden text is interpreted as executable formatting/behavioral directives rather than as data to summarize. This allows the attacker to steer the assistant's output: rather than producing a faithful synopsis of the email, Copilot renders attacker-authored content -- for example, a fake "unrecognized sign-in" security alert with a call-to-action link -- inside the summary UI that the user implicitly trusts as system-generated. In more advanced variants, the injected instructions direct Copilot to pull additional context from connected Microsoft 365 data sources (Teams messages, OneDrive files, SharePoint documents) via Microsoft Graph, blending real internal data into the attacker-controlled narrative to increase credibility, and creating a secondary information-disclosure risk (CVSS Confidentiality:High) alongside the phishing-enablement risk (Integrity:Low). The vulnerability class is not unique to Microsoft: 0DIN researchers documented an analogous XPIA against Google Gemini for Workspace using the same hidden-instruction-in-email technique to produce system-styled phishing warnings. A related but separate Copilot Personal flaw ("Reprompt", reported by Varonis) demonstrates a complementary attack surface in the same product family: a single malicious link abuses the Copilot web UI's `q` URL parameter to inject a prompt directly (Parameter-to-Prompt / P2P injection), then uses a "double-request" trick to bypass safeguards that only check the first turn of a conversation, and a server-driven "chain-request" technique to issue follow-up instructions based on Copilot's prior responses -- enabling continuous, attacker-directed exfiltration of emails, files, and MFA codes from a single click, without any attachment or credential compromise. Microsoft confirmed CVE-2026-26133 on January 28, 2026 and shipped a phased mitigation (rendering/link-handling behavior changes across the affected Outlook and Teams summarization surfaces) completing rollout on March 11, 2026, one day before the CVE and technical writeup were published.
MITRE ATT&CK / ATLAS techniques used in TL-2026-1538
Impact
AML.T0048.003 External Harms
Execution
AML.T0051.001 LLM Prompt Injection; AML.T0053 AI Agent Tool Invocation; T1204 User Execution; T1204.001 User Execution
Initial Access
AML.T0052 Phishing; T1566 Phishing
Exfiltration
AML.T0057 LLM Data Leakage; T1041 Exfiltration Over C2 Channel
Resource Development
AML.T0066 Retrieval Content Crafting; T1583 Acquire Infrastructure
Defense Evasion
AML.T0067 LLM Trusted Output Components Manipulation; T1027 Obfuscated Files or Information; T1036 Masquerading
Collection
T1005 Data from Local System; T1114 Email Collection; T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Command and Control
credential-access
Credential Access
T1528 Steal Application Access Token; T1621 Multi-Factor Authentication Request Generation
Lateral Movement
T1550 Use Alternate Authentication Material
Discovery
T1580 Cloud Infrastructure Discovery
reconnaissance
T1598 Phishing for Information
stealth
Affected products and versions in CVE-2026-26133
- Microsoft — Microsoft 365 Copilot (Outlook Summarize / Copilot pane, Teams Copilot summarization)
Vulnerable versions: Microsoft 365 Copilot cloud service, all tenants prior to patch rollout completion
Fixed in: Microsoft 365 Copilot cloud service post March 11, 2026 rollout - Microsoft — Outlook (Web, Desktop, iOS, Android) Copilot integration
Vulnerable versions: All Copilot-enabled Outlook clients prior to patch
Fixed in: Patched service-side, no client version pin published - Microsoft — Microsoft Teams Copilot summarization
Vulnerable versions: All Copilot-enabled Teams tenants prior to patch
Fixed in: Patched service-side, no client version pin published
Remediation for CVE-2026-26133
Patches
- Microsoft 365 Copilot service-side rendering and link-handling fix, phased rollout February 17, 2026 - March 11, 2026, published as CVE-2026-26133 on March 12, 2026
Immediate actions
- Confirm tenant is on the post-March-11-2026 Microsoft 365 Copilot service build (cloud-side fix, no client action required for most surfaces)
- Educate users that Copilot-generated summaries and security-style alerts are not authoritative system notifications and should not be trusted for security decisions
- Enable Safe Links / URL rewriting in Exchange Online Protection and Defender for Office 365 so links surfaced inside Copilot summaries are still scanned
- Review Outlook and Teams Copilot usage logs (Microsoft Purview / Unified Audit Log) for anomalous summarization requests correlating with suspicious inbound mail
Workarounds
- Disable or restrict Copilot Summarize/Chat surfaces in Outlook and Teams for high-risk user groups until confirmed patched
- Configure mail flow rules to strip or flag hidden/obfuscated HTML content (invisible text, off-screen divs, transparent fonts) in inbound external mail
Longer-term hardening
- Deploy prompt-injection-aware email content filtering that flags HTML/CSS obfuscation techniques (hidden text, zero-size fonts, off-canvas positioning, color-matched text)
- Adopt AI red-teaming / XPIA-specific testing for any LLM feature that ingests untrusted external content (email, chat, documents) before granting it UI real estate that implies system trust
- Architect LLM-integrated productivity features so system instructions and untrusted content are cryptographically or structurally separated (instruction/data channel isolation) rather than concatenated into a single prompt
- Monitor for the related 'Reprompt' class of attack (URL-parameter prompt injection via the Copilot `q` parameter) and apply the same phishing-awareness training to Copilot Personal users
CVEs associated with CVE-2026-26133
CVE-2026-26133
Weaknesses (CWE) in CVE-2026-26133
CWE-77, CWE-1427
Timeline of CVE-2026-26133
- 0DIN publishes 'Phishing For Gemini,' documenting the structurally identical hidden HTML/CSS indirect-prompt-injection phishing technique against Google Gemini for Workspace's email summarization -- prior art Permiso cites in its Copilot write-up.
- Permiso Security researcher Andi Ahmeti reports the Copilot cross-prompt injection technique to Microsoft.
- Microsoft acknowledges the report and begins internal triage.
- Microsoft confirms internal reproduction of the vulnerability across Outlook and Teams Copilot summarization surfaces.
- Microsoft completes reproduction and begins planning mitigation across the affected Copilot surfaces.
- Microsoft begins phased mitigation rollout across affected Copilot summarization surfaces.
- Microsoft completes the phased patch rollout across all affected Outlook and Teams Copilot surfaces.
- CVE-2026-26133 is published (CVSS 7.1) and Permiso Security releases the full technical writeup 'CO-PILOT, DISENGAGE AUTOPHISH'.
- CVE-2026-26133 is published in the NVD and via Microsoft's Security Update Guide, assigning CVSS 3.1 base score 7.1 (HIGH) and CWE-77.
- Varonis publishes 'Reprompt', a related single-click Microsoft Copilot Personal prompt-injection attack (URL `q`-parameter injection, double-request bypass, chain-request exfiltration) capable of stealing emails, files, and MFA codes, covered by The Hacker News.
- Varonis Threat Labs discloses 'SearchLeak', a parallel vulnerability chain affecting Microsoft 365 Copilot Enterprise search/summarization surfaces; distinct from Reprompt (which targets Copilot Personal) and referenced alongside the separate 'EchoLeak' AI vulnerability class requiring user prompts or plugin interaction.
Update history for TL-2026-1538
- 2026-09-09 — Cross-Prompt Injection in Microsoft Copilot Email/Teams Summarization Enables Phishing (CVE-2026-26133): What changed No severity, exploitability, or CVSS escalation (still HIGH / THEORETICAL / 7.1 in both reports). The newer report adds a second CWE (CWE-1427, LLM-prompt-injection-specific), confirms no in-the-wild exploitation and absence fr
Sources cited for CVE-2026-26133
- CO-PILOT, DISENGAGE AUTOPHISH: The New Phishing Surface Hiding Inside AI Email Summaries
- CVE-2026-26133: M365 Copilot Information Disclosure Flaw
- CVE-2026-26133 vulnerability details
- CVE-2026-26133: Microsoft 365 Copilot Information Disclosure and the Confidence Signal
- Copilot Can Be Weaponized: What CVE-2026-26133 Means for Microsoft 365 Admins
- Microsoft: Microsoft Copilot Email and Teams Summarization Vulnerability Enables Phishing Attacks
- One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
- Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data
- M365 Copilot AI Prompt Injection Attack Patched; Salesforce Misconfigurations Risk Data Leaks; Patch Tuesday: Microsoft and Adobe
- Microsoft 365 Copilot Security: Enterprise CISO Guide 2026
Threats related to CVE-2026-26133
Detection coverage for TL-2026-1538
As of 2026-09-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1538 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.