Microsoft Copilot Email and Teams Summarization Vulnerability Enables Phishing Attacks
Recent developments have highlighted a critical cross-prompt injection vulnerability (XPIA) within Microsoft 365 Copilot's email summarization feature, identified as CVE-2026-26133. This vulnerability enables attackers to manipulate Copilot’s output by…
Recent developments have highlighted a critical cross-prompt injection vulnerability (XPIA) within Microsoft 365 Copilot's email summarization feature, identified as CVE-2026-26133. This vulnerability enables attackers to manipulate Copilot’s output by embedding malicious text within regular emails, potentially leading to phishing attacks without the use of traditional exploit methods.
Microsoft confirmed the vulnerability on January 28, 2026. Mitigations began on February 17, with a full patch rollout completed by March 11. The CVE was officially published on March 12, 2026, acknowledging Andi Ahmeti from Permiso Security for the discovery.
The vulnerability exploits Copilot's summarization process, which treats embedded text in emails as executable instructions. This allows attackers to craft emails that alter Copilot's summaries, making them appear as legitimate system notifications.
Permiso Security conducted tests on three common Copilot email summarization interfaces:
Mitigations began on February 17, with a full patch rollout completed by March 11.
Outlook Summarize Button: Showed unpredictable behavior when processing emails with embedded instructions, sometimes leaking parts of the injected commands. Outlook Copilot Pane: Generally ignored injected instructions, but compliance varied with specific email client configurations. Teams Copilot: Consistently produced summaries with attacker-influenced content.
This vulnerability is exacerbated by Copilot's ability to access multiple Microsoft 365 resources, potentially leading to sensitive data exfiltration through crafted links.
Organizations utilizing Microsoft 365 Copilot should consider the following steps:
Apply the March 2026 patch immediately — Ensure the latest security updates are implemented. Audit Copilot permissions — Limit retrieval scope to necessary operations, restricting cross-app access. Enable Microsoft Purview sensitivity labels and DLP policies — These measures help contain potential data leaks. Enable Safe Links — Use URL reputation checks for links rendered within Copilot. User awareness — Educate users about the potential for attacker-manipulated content in AI-generated summaries. Monitor Copilot activity logs — Watch for unusual retrieval patterns that may indicate exploitation attempts.
Based on reporting by Cyber Security News.
