A newly disclosed SearchLeak vulnerability in Microsoft 365 Copilot Enterprise exposed a critical pathway for attackers to steal sensitive organizational data through a specially crafted URL. The flaw chain, now tracked as CVE-2026-42824, was patched by Microsoft earlier this month and assigned a critical severity rating due to its potential impact.
First seen on thecyberexpress.com
Jump to article: thecyberexpress.com/searchleak-vulnerability-microsoft-365-copilot/
![]()

