Microsoft 365 Copilot SearchLeak Patched
Analysis based on 6 articles · First reported Jun 15, 2026 · Last updated Jun 16, 2026
The discovery of the SearchLeak vulnerability in Microsoft Copilot Enterprise by Varonis Systems and its subsequent patching by Microsoft could lead to increased scrutiny of AI-powered enterprise tools. While Microsoft has addressed the flaw, the event highlights potential new attack surfaces in cloud services, which may prompt companies to re-evaluate their cybersecurity strategies and potentially increase spending on security solutions, benefiting cybersecurity firms like Varonis Systems.
Security researchers at Varonis Systems Threat Labs discovered a critical vulnerability chain, dubbed SearchLeak (CVE-2026-42824), in Microsoft Copilot Enterprise. This flaw allowed attackers to steal sensitive corporate data, including emails, MFA codes, calendar details, and confidential files, with a single click on a legitimate Microsoft domain link. The attack combined a Parameter-to-Prompt (P2P) Injection, an HTML rendering race condition, and a Server-Side Request Forgery (SSRF) via BingX's image search endpoint. Microsoft has since fully patched the vulnerability server-side, requiring no user action for mitigation. The incident underscores how AI assistants can create new attack surfaces by reactivating previously unexploitable classic vulnerabilities.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard