Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway.

Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway.
Published in : 15 Apr 2026

Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway.

Microsoft assigned CVE-2026-21520, a CVSS 7.5 indirect prompt injection vulnerability, to Copilot Studio. Capsule Security discovered the flaw, coordinated disclosure with Microsoft, and the patch was deployed on January...

Read full article from source