Microsoft 365 Copilot Enterprise SearchLeak remote code execution flaw (CVE-2026-42824)
Vulnerability
Summary
Hide ▲
Show ▼
Microsoft 365 Copilot Enterprise Search has a critical vulnerability chain, SearchLeak, that could let a user leak emails, calendar details, MFA codes, and indexed files after clicking a trusted microsoft.com link. The chain used the `q` parameter, an HTML rendering race, and Bing's Search by Image as an exfiltration proxy. Microsoft assigned CVE-2026-42824 and said it mitigated the flaw on its backend, while Varonis Threat Labs reported a proof-of-concept rather than observed exploitation.
Related Happenings
KongTuke Microsoft Teams initial access campaign
Campaign
H score42
First: 14.05.2026 15:12
Last: 14.05.2026 15:12
Sources 1
About this happening:
The KongTuke campaign now uses Microsoft Teams social engineering to gain persistent access to corporate networks, shortening initial compromise to under five minute...
KongTuke Microsoft Teams initial access campaign
CampaignAbout this happening: The KongTuke campaign now uses Microsoft Teams social engineering to gain persistent access to corporate networks, shortening initial compromise to under five minute...
Microsoft Windows 365 Office installation disruption
Service Disruption
H score0
First: 13.05.2026 14:53
Last: 13.05.2026 14:53
Sources 1
About this happening:
The Windows 365 service update has introduced a configuration change that is blocking Office downloads and installs for some customers, disrupting access on cloud PCs....
Microsoft Windows 365 Office installation disruption
Service DisruptionAbout this happening: The Windows 365 service update has introduced a configuration change that is blocking Office downloads and installs for some customers, disrupting access on cloud PCs....
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-velocity exploit campaign
Campaign
H score59
First: 06.04.2026 19:56
Last: 06.04.2026 19:56
Sources 1
About this happening:
Storm-1175 is running a high-velocity exploit campaign that rapidly turns access into Medusa ransomware deployment, creating risk of data exfiltration and encrypte...
Storm-1175 high-velocity exploit campaign
CampaignAbout this happening: Storm-1175 is running a high-velocity exploit campaign that rapidly turns access into Medusa ransomware deployment, creating risk of data exfiltration and encrypte...
Storm-2561 SEO-poisoning VPN credential-theft campaign
Campaign
H score37
First: 13.03.2026 15:38
Last: 13.03.2026 15:38
Sources 1
About this happening:
The Storm-2561 group is running a credential-theft campaign that uses SEO poisoning and fake VPN clients to steal VPN credentials from people searching for ent...
Storm-2561 SEO-poisoning VPN credential-theft campaign
CampaignAbout this happening: The Storm-2561 group is running a credential-theft campaign that uses SEO poisoning and fake VPN clients to steal VPN credentials from people searching for ent...
Timeline
-
15.06.2026 16:00 3 articles · 1mo ago
SearchLeak chains Copilot Enterprise flaws to steal mailbox and SharePoint data
Initial DisclosureVaronis describes SearchLeak, a three-stage attack chain in Microsoft 365 Copilot Enterprise that combines parameter-to-prompt injection, an HTML rendering race condition, and a Bing SSRF/CSP bypass to exfiltrate mailbox, OneDrive, or SharePoint data through a specially crafted URL. Microsoft assigned CVE-2026-42824 a critical rating and has already fixed it, with no user action required to mitigate the threat.
Show sources
- New attack turned Microsoft 365 Copilot into 1-click data theft tool — www.bleepingcomputer.com — 15.06.2026 16:00
- New attack turned Microsoft 365 Copilot into 1-click data theft tool — www.bleepingcomputer.com — 15.06.2026 16:00
- One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes — thehackernews.com — 15.06.2026 18:09