Microsoft 365 Copilot work tab DLP bypass security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Microsoft 365 Copilot has a DLP-bypass vulnerability in its work tab chat that can summarize confidential email content, creating a risk that protected messages are processed by automated tools. The flaw affects mail stored in Sent Items and Drafts, including messages with confidentiality and sensitivity labels. Microsoft says a fix began rolling out in early February while it continues to monitor the deployment.
Related Happenings
Microsoft Exchange Server spoofing/XSS flaw under active exploitation (CVE-2026-42897)
Vulnerability
First: 15.05.2026 09:19
Last: 15.05.2026 09:19
Sources 1
About this happening:
**CVE-2026-42897** is an **actively exploited** **spoofing/XSS** flaw in **on-premises Microsoft Exchange Server** that can let attackers trigger **arbitrary JavaScript** in a bro...
Microsoft Exchange Server spoofing/XSS flaw under active exploitation (CVE-2026-42897)
VulnerabilityAbout this happening: **CVE-2026-42897** is an **actively exploited** **spoofing/XSS** flaw in **on-premises Microsoft Exchange Server** that can let attackers trigger **arbitrary JavaScript** in a bro...
Microsoft Windows 365 Office installation disruption
Service Disruption
First: 13.05.2026 14:53
Last: 13.05.2026 14:53
Sources 1
About this happening:
The **Windows 365** service update has introduced a **configuration change** that is blocking **Office downloads and installs** for some customers, disrupting access on cloud PCs....
Microsoft Windows 365 Office installation disruption
Service DisruptionAbout this happening: The **Windows 365** service update has introduced a **configuration change** that is blocking **Office downloads and installs** for some customers, disrupting access on cloud PCs....
Microsoft Windows RDP security warning dialog rendering issue after April 2026 updates
Security Tool/Service
First: 28.04.2026 12:51
Last: 28.04.2026 12:51
Sources 1
About this happening:
**Microsoft** confirmed that newly introduced **Windows security warnings** for opening **Remote Desktop (.rdp) files** can display incorrectly, reducing users' ability to review...
Microsoft Windows RDP security warning dialog rendering issue after April 2026 updates
Security Tool/ServiceAbout this happening: **Microsoft** confirmed that newly introduced **Windows security warnings** for opening **Remote Desktop (.rdp) files** can display incorrectly, reducing users' ability to review...
Microsoft Outlook.com outage causing sign-in failures
Service Disruption
First: 27.04.2026 15:03
Last: 27.04.2026 15:03
Sources 1
About this happening:
Microsoft's **Outlook.com** is experiencing an **ongoing outage** that is blocking sign-ins and mailbox access, leaving some customers unable to use email normally. The disruption...
Microsoft Outlook.com outage causing sign-in failures
Service DisruptionAbout this happening: Microsoft's **Outlook.com** is experiencing an **ongoing outage** that is blocking sign-ins and mailbox access, leaving some customers unable to use email normally. The disruption...
Microsoft Edge regression disrupts Teams meeting joins
Service Disruption
First: 23.04.2026 16:18
Last: 23.04.2026 16:18
Sources 1
About this happening:
A **Microsoft Edge** regression is preventing some **Windows** users from joining **Microsoft Teams** meetings, causing a limited-scope access disruption for scheduled and link-ba...
Microsoft Edge regression disrupts Teams meeting joins
Service DisruptionAbout this happening: A **Microsoft Edge** regression is preventing some **Windows** users from joining **Microsoft Teams** meetings, causing a limited-scope access disruption for scheduled and link-ba...
Timeline
-
18.02.2026 14:03 2 articles · 3mo ago
Microsoft 365 Copilot work tab bug detected
Detection Ioc UpdateMicrosoft identified a Microsoft 365 Copilot work tab chat bug on January 21 that incorrectly reads and summarizes emails stored in users' Sent Items and Drafts folders, including messages with confidentiality labels and configured DLP policies meant to restrict automated access.
Show sources
- Microsoft says bug causes Copilot to summarize confidential emails — www.bleepingcomputer.com — 18.02.2026 14:03
- Microsoft says bug causes Copilot to summarize confidential emails — www.bleepingcomputer.com — 18.02.2026 14:03
-
18.02.2026 14:03 2 articles · 3mo ago
Microsoft begins fix rollout and monitors Copilot issue
Mitigation Patch UpdateMicrosoft confirmed an unspecified code error, said it began rolling out a fix in early February for the Microsoft 365 Copilot work tab issue, and said it is monitoring deployment while reaching out to a subset of affected users to verify that the fix is working.
Show sources
- Microsoft says bug causes Copilot to summarize confidential emails — www.bleepingcomputer.com — 18.02.2026 14:03
- Microsoft adds Copilot data controls to all storage locations — www.bleepingcomputer.com — 24.02.2026 19:30