CVE-2026-26133: Cross-Prompt Injection in Microsoft Copilot Email/Teams Summarization Enables AI-Mediated Phishing

CVE-2026-26133 (TL-2026-1538), also tracked as Copilot Cross-Prompt Injection, is a high-severity software vulnerability scored CVSS 7.1, first published 2026-03-12 and last reviewed 2026-09-09. It has no confirmed attribution, affects Microsoft Microsoft 365 Copilot (Outlook Summarize / Copilot pane, references 1 CVE (CVE-2026-26133), maps to 26 MITRE ATT&CK / ATLAS techniques (AML.T0048.003, AML.T0051.001, AML.T0052), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-1538

Threat ID
TL-2026-1538
Also known as
Copilot Cross-Prompt Injection, CO-PILOT DISENGAGE AUTOPHISH, Copilot AI-Mediated Phishing
Severity
HIGH
CVSS
7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
Status
PATCHED
Category
VULNERABILITY
First published
2026-03-12
Last reviewed
2026-09-09
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
all sectors using microsoft 365 copilot, enterprise, government administration, finance, health, technology
Target regions
Global
Detection rules
9
Indicators of compromise
30
Updates
2026-09-09 · revalidated 1× · latest source

Malware and tooling in CVE-2026-26133

Malware and tooling: Microsoft 365 Copilot, Outlook Copilot Summarize / Copilot pane, Teams Copilot summarization

A cross-prompt injection (XPIA) flaw in Microsoft 365 Copilot's email and Teams summarization surfaces let attackers embed HTML/CSS-hidden instructions in ordinary emails that the underlying LLM ingests but the human recipient never sees, hijacking Copilot's trusted summary UI to present fake security alerts and phishing links as system-generated content. Disclosed by Permiso Security researcher Andi Ahmeti; Microsoft assigned CVSS 7.1 (CVE-2026-26133) and completed a phased patch rollout by March 11, 2026.

How CVE-2026-26133 works

CVE-2026-26133 is an AI command injection / information disclosure vulnerability (CWE-77) in Microsoft 365 Copilot's summarization pipeline. The attack requires no attachment, macro, or traditional exploit code: an attacker only needs to land an ordinary email in the victim's inbox. Using HTML/CSS rendering tricks (e.g., zero-size fonts, off-screen positioning, matching foreground/background colors, or comment-like markup), the attacker embeds instruction-like text within the raw message body. This text is invisible to the human reader in the Outlook reading pane but is fully present in the raw content that Copilot's underlying model ingests when a user clicks "Summarize" in Outlook, opens the Outlook Copilot chat pane, or has the email surfaced through Teams Copilot. Because Copilot does not sufficiently separate trusted system instructions from untrusted email content (insufficient input validation/sanitization per CWE-77), the hidden text is interpreted as executable formatting/behavioral directives rather than as data to summarize. This allows the attacker to steer the assistant's output: rather than producing a faithful synopsis of the email, Copilot renders attacker-authored content -- for example, a fake "unrecognized sign-in" security alert with a call-to-action link -- inside the summary UI that the user implicitly trusts as system-generated. In more advanced variants, the injected instructions direct Copilot to pull additional context from connected Microsoft 365 data sources (Teams messages, OneDrive files, SharePoint documents) via Microsoft Graph, blending real internal data into the attacker-controlled narrative to increase credibility, and creating a secondary information-disclosure risk (CVSS Confidentiality:High) alongside the phishing-enablement risk (Integrity:Low). The vulnerability class is not unique to Microsoft: 0DIN researchers documented an analogous XPIA against Google Gemini for Workspace using the same hidden-instruction-in-email technique to produce system-styled phishing warnings. A related but separate Copilot Personal flaw ("Reprompt", reported by Varonis) demonstrates a complementary attack surface in the same product family: a single malicious link abuses the Copilot web UI's `q` URL parameter to inject a prompt directly (Parameter-to-Prompt / P2P injection), then uses a "double-request" trick to bypass safeguards that only check the first turn of a conversation, and a server-driven "chain-request" technique to issue follow-up instructions based on Copilot's prior responses -- enabling continuous, attacker-directed exfiltration of emails, files, and MFA codes from a single click, without any attachment or credential compromise. Microsoft confirmed CVE-2026-26133 on January 28, 2026 and shipped a phased mitigation (rendering/link-handling behavior changes across the affected Outlook and Teams summarization surfaces) completing rollout on March 11, 2026, one day before the CVE and technical writeup were published.

MITRE ATT&CK / ATLAS techniques used in TL-2026-1538

Impact

AML.T0048.003 External Harms

Execution

AML.T0051.001 LLM Prompt Injection; AML.T0053 AI Agent Tool Invocation; T1204 User Execution; T1204.001 User Execution

Initial Access

AML.T0052 Phishing; T1566 Phishing

Exfiltration

AML.T0057 LLM Data Leakage; T1041 Exfiltration Over C2 Channel

Resource Development

AML.T0066 Retrieval Content Crafting; T1583 Acquire Infrastructure

Defense Evasion

AML.T0067 LLM Trusted Output Components Manipulation; T1027 Obfuscated Files or Information; T1036 Masquerading

Collection

T1005 Data from Local System; T1114 Email Collection; T1213 Data from Information Repositories; T1530 Data from Cloud Storage

Command and Control

T1102 Web Service

credential-access

T1187 Forced Authentication

Credential Access

T1528 Steal Application Access Token; T1621 Multi-Factor Authentication Request Generation

Lateral Movement

T1550 Use Alternate Authentication Material

Discovery

T1580 Cloud Infrastructure Discovery

reconnaissance

T1598 Phishing for Information

stealth

T1684.001 Impersonation

Affected products and versions in CVE-2026-26133

  • Microsoft — Microsoft 365 Copilot (Outlook Summarize / Copilot pane, Teams Copilot summarization)
    Vulnerable versions: Microsoft 365 Copilot cloud service, all tenants prior to patch rollout completion
    Fixed in: Microsoft 365 Copilot cloud service post March 11, 2026 rollout
  • Microsoft — Outlook (Web, Desktop, iOS, Android) Copilot integration
    Vulnerable versions: All Copilot-enabled Outlook clients prior to patch
    Fixed in: Patched service-side, no client version pin published
  • Microsoft — Microsoft Teams Copilot summarization
    Vulnerable versions: All Copilot-enabled Teams tenants prior to patch
    Fixed in: Patched service-side, no client version pin published

Remediation for CVE-2026-26133

Patches

  • Microsoft 365 Copilot service-side rendering and link-handling fix, phased rollout February 17, 2026 - March 11, 2026, published as CVE-2026-26133 on March 12, 2026

Immediate actions

  • Confirm tenant is on the post-March-11-2026 Microsoft 365 Copilot service build (cloud-side fix, no client action required for most surfaces)
  • Educate users that Copilot-generated summaries and security-style alerts are not authoritative system notifications and should not be trusted for security decisions
  • Enable Safe Links / URL rewriting in Exchange Online Protection and Defender for Office 365 so links surfaced inside Copilot summaries are still scanned
  • Review Outlook and Teams Copilot usage logs (Microsoft Purview / Unified Audit Log) for anomalous summarization requests correlating with suspicious inbound mail

Workarounds

  • Disable or restrict Copilot Summarize/Chat surfaces in Outlook and Teams for high-risk user groups until confirmed patched
  • Configure mail flow rules to strip or flag hidden/obfuscated HTML content (invisible text, off-screen divs, transparent fonts) in inbound external mail

Longer-term hardening

  • Deploy prompt-injection-aware email content filtering that flags HTML/CSS obfuscation techniques (hidden text, zero-size fonts, off-canvas positioning, color-matched text)
  • Adopt AI red-teaming / XPIA-specific testing for any LLM feature that ingests untrusted external content (email, chat, documents) before granting it UI real estate that implies system trust
  • Architect LLM-integrated productivity features so system instructions and untrusted content are cryptographically or structurally separated (instruction/data channel isolation) rather than concatenated into a single prompt
  • Monitor for the related 'Reprompt' class of attack (URL-parameter prompt injection via the Copilot `q` parameter) and apply the same phishing-awareness training to Copilot Personal users

CVEs associated with CVE-2026-26133

CVE-2026-26133

Weaknesses (CWE) in CVE-2026-26133

CWE-77, CWE-1427

Timeline of CVE-2026-26133

  • 0DIN publishes 'Phishing For Gemini,' documenting the structurally identical hidden HTML/CSS indirect-prompt-injection phishing technique against Google Gemini for Workspace's email summarization -- prior art Permiso cites in its Copilot write-up.
  • Permiso Security researcher Andi Ahmeti reports the Copilot cross-prompt injection technique to Microsoft.
  • Microsoft acknowledges the report and begins internal triage.
  • Microsoft confirms internal reproduction of the vulnerability across Outlook and Teams Copilot summarization surfaces.
  • Microsoft completes reproduction and begins planning mitigation across the affected Copilot surfaces.
  • Microsoft begins phased mitigation rollout across affected Copilot summarization surfaces.
  • Microsoft completes the phased patch rollout across all affected Outlook and Teams Copilot surfaces.
  • CVE-2026-26133 is published (CVSS 7.1) and Permiso Security releases the full technical writeup 'CO-PILOT, DISENGAGE AUTOPHISH'.
  • CVE-2026-26133 is published in the NVD and via Microsoft's Security Update Guide, assigning CVSS 3.1 base score 7.1 (HIGH) and CWE-77.
  • Varonis publishes 'Reprompt', a related single-click Microsoft Copilot Personal prompt-injection attack (URL `q`-parameter injection, double-request bypass, chain-request exfiltration) capable of stealing emails, files, and MFA codes, covered by The Hacker News.
  • Varonis Threat Labs discloses 'SearchLeak', a parallel vulnerability chain affecting Microsoft 365 Copilot Enterprise search/summarization surfaces; distinct from Reprompt (which targets Copilot Personal) and referenced alongside the separate 'EchoLeak' AI vulnerability class requiring user prompts or plugin interaction.

Update history for TL-2026-1538

Sources cited for CVE-2026-26133

Threats related to CVE-2026-26133

Detection coverage for TL-2026-1538

As of 2026-09-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1538 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats