Changeflow GovPing Data Privacy & Cybersecurity Microsoft 365 Copilot Vulnerabilities Advisory
Priority review Notice Added Final

Microsoft 365 Copilot Vulnerabilities Advisory

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 19th, 2026
Detected March 20th, 2026
Email

Summary

CERT-Bund has issued an advisory regarding multiple vulnerabilities in Microsoft 365 Copilot, with a CVSS base score of 8.9. These vulnerabilities could allow remote attackers to disclose information, manipulate data, and gain elevated privileges. Mitigation measures are available.

What changed

CERT-Bund has released an advisory (WID-SEC-2026-0795) detailing multiple critical vulnerabilities affecting Microsoft 365 Copilot and Microsoft 365 Copilot BizChat. The vulnerabilities have a high CVSS base score of 8.9 and a temporal score of 7.7. Exploitation could lead to unauthorized information disclosure, data manipulation, and privilege escalation.

Organizations utilizing Microsoft 365 Copilot should review the advisory and implement available mitigation strategies to protect their systems. The advisory indicates that remote attacks are possible, and prompt action is recommended to address the security risks associated with these vulnerabilities.

What to do next

  1. Review CERT-Bund advisory WID-SEC-2026-0795 for detailed vulnerability information.
  2. Implement available mitigation measures for Microsoft 365 Copilot.
  3. Assess potential impact of vulnerabilities on data confidentiality and integrity.

Source document (simplified)

[WID-SEC-2026-0795] Microsoft 365 Copilot: Mehrere Schwachstellen CVSS Base Score 8.9 (hoch) CVSS Temporal Score 7.7 (hoch) Remoteangriff ja Datum 19.03.2026 Stand 20.03.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Sonstiges
  • Windows

Produktbeschreibung

Microsoft Copilot ist ein KI-Assistent, der in verschiedene Microsoft-Produkte integriert werden kann.

Produkte

19.03.2026
- Microsoft 365 Copilot

  • Microsoft 365 Copilot BizChat

Angriff

Angriff

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Microsoft 365 Copilot ausnutzen, um Informationen offenzulegen, Daten zu manipulieren und erweiterte Berechtigungen zu erlangen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 19th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
WID-SEC-2026-0795

Who this affects

Applies to
Technology companies
Industry sector
5112 Software & Technology
Activity scope
AI Assistant Integration Data Security
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Artificial Intelligence Data Security

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.