aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI & LLM Vulnerabilities

Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.

to
Export CSV
94 items

CVE-2026-85887: Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose informat

highvulnerability
security
Sep 17, 2026
CVE-2026-85887

A flaw in Microsoft 365 Copilot's permission settings allows someone with authorized access to improperly view sensitive information across a network. The issue stems from incorrect assignment of permissions (access rules) to a critical resource (important data or system component), meaning the AI tool isn't properly restricting who can see what.

NVD/CVE Database

CVE-2026-85885: Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized

criticalvulnerability
security
Sep 17, 2026
CVE-2026-85885

M365 Copilot has a command injection vulnerability (a flaw where special characters in user input can trick the system into running unintended commands), which allows an authorized attacker to gain higher privileges over a network. The vulnerability affects users who already have some level of access to the system.

CVE-2026-78501: Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business

highvulnerability
security
Sep 17, 2026
CVE-2026-78501

Microsoft 365 Copilot's Business Chat has a vulnerability where special characters are not properly filtered before being used in commands, allowing attackers to inject malicious commands (command injection, where an attacker sneaks unauthorized instructions into a system by exploiting how it processes input). This could let unauthorized people access and steal sensitive information across the network.

CVE-2026-68791: Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network

highvulnerability
security
Sep 17, 2026
CVE-2026-68791

Azure Machine Learning contains a vulnerability where authorization checks (the system that verifies whether a user is allowed to perform an action) are not working correctly, allowing an attacker without permission to access and steal sensitive information over the internet.

CVE-2026-55946: Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut

mediumvulnerability
security
Sep 17, 2026
CVE-2026-55946

Microsoft Copilot has a command injection vulnerability (a flaw where special characters in user input are not properly filtered, allowing attackers to execute unintended commands), which lets an unauthorized attacker access and leak sensitive information over a network.

GHSA-96p9-rh4f-92cf: Windows ML CLI: CORS misconfig enables localhost RCE

highvulnerability
security
Sep 8, 2026
CVE-2026-84452

The Windows ML CLI tool exposes commands over HTTP on localhost without authentication and sets CORS (cross-origin resource sharing, which controls what websites can access a server) to allow all origins via a wildcard. This means any website you visit can call the CLI endpoint, and if you use the '--trust-remote-code' flag with a malicious model repository, an attacker can execute arbitrary code on your computer when the server imports that model.

CVE-2026-81381: Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclos

mediumvulnerability
security
Sep 8, 2026
CVE-2026-81381

GitHub Copilot and Visual Studio Code have a security flaw where credentials (secret login information) are not properly protected, allowing an attacker on a network to steal and expose this sensitive data.

CVE-2026-81380: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio

mediumvulnerability
security
Sep 8, 2026
CVE-2026-81380

GitHub Copilot and Visual Studio Code have a vulnerability where special characters in commands aren't properly filtered, allowing an attacker to inject malicious commands (command injection, where an attacker manipulates input to run unintended commands) and access sensitive information over a network.

CVE-2026-85686: ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetch

highvulnerability
security
Sep 4, 2026
CVE-2026-85686

ms-swift 4.5.2 has a server-side request forgery vulnerability (SSRF, where an attacker tricks a server into making requests to places it shouldn't), in its OpenAI-compatible API that handles media files. Attackers without authentication can provide fake image, audio, or video URLs that force the server to request internal services and cloud metadata, potentially exposing sensitive information.

CVE-2026-80098: Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges

criticalvulnerability
security
Sep 3, 2026
CVE-2026-80098

Copilot Studio has a security flaw where it fails to properly verify cryptographic signatures (mathematical proofs that data comes from a trusted source), allowing an attacker to gain elevated privileges (higher access levels) on a network without authorization.

Microsoft Outlook and OpenAI's ChatGPT Work are experiencing user outages

infoincident
security
Aug 31, 2026

OpenAI's ChatGPT Work (an enterprise AI agent) and Microsoft Outlook both experienced outages on Monday, with users unable to access or use these services for several hours. OpenAI reported elevated errors and latency in ChatGPT Work, while Microsoft had issues with Exchange Online (the cloud service that powers Outlook), though the outages appeared to be unrelated.

CVE-2026-58616: Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft E

mediumvulnerability
security
Aug 28, 2026
CVE-2026-58616

A race condition (a bug where two processes access the same resource at the same time, causing unpredictable behavior) exists in Microsoft Edge's Copilot Chat feature that allows an authorized attacker to leak sensitive information over a network.

CVE-2026-69836: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability

criticalvulnerability
security
Aug 20, 2026
CVE-2026-69836🔥 Actively Exploited

CVE-2026-69855: Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information o

highvulnerability
security
Aug 20, 2026
CVE-2026-69855

CVE-2026-69855 is a server-side request forgery vulnerability (SSRF, a flaw that lets attackers trick a server into making requests to internal systems) in Microsoft Copilot running on Azure. An authorized attacker can exploit this to leak sensitive information across a network.

CVE-2026-24301: Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut

highvulnerability
security
Aug 18, 2026
CVE-2026-24301

CVE-2026-24301 is a command injection vulnerability (a weakness where an attacker hides malicious commands in user input to trick a program into executing them) in Microsoft Copilot that allows an unauthorized attacker to access and steal information over a network. The vulnerability stems from improper neutralization of special elements used in commands. The CVSS severity score (a 0-10 rating of how dangerous a vulnerability is) has not yet been assigned by NIST.

CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability

highvulnerability
security
Aug 17, 2026
CVE-2026-55040🔥 Actively Exploited

CVE-2026-70335: Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual

highvulnerability
security
Aug 11, 2026
CVE-2026-70335

CVE-2026-70335 is a vulnerability in GitHub Copilot and Visual Studio Code that allows improper neutralization of special elements in OS commands (OS command injection, where an attacker can execute arbitrary system commands). An unauthorized attacker could exploit this to elevate their privileges locally on an affected system.

CVE-2026-65675: No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security

highvulnerability
security
Aug 11, 2026
CVE-2026-65675

CVE-2026-65675 is a vulnerability in Visual Studio Code's CoPilot Chat Extension that allows an unauthorized attacker to bypass a security feature over a network. The vulnerability has not yet been assigned a complete severity rating or detailed weakness classification by NIST.

GHSA-p5rm-jg5c-8c77: Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)

mediumvulnerability
security
Jul 24, 2026

Microsoft Kiota, a tool that generates AI plugin manifests from API descriptions, has a path traversal vulnerability (CWE-22, a security flaw where attackers access files outside intended directories) in how it validates file references. An attacker controlling the API description can use percent-encoding (a way of representing special characters as %XX codes) to bypass safety checks and reference files outside the plugin package, potentially exposing sensitive files like `/etc/passwd`. The initial fix in v1.32.5 failed because it checked the encoded string before decoding it, allowing attackers to hide traversal patterns in encoded form.

CVE-2026-50517: Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

criticalvulnerability
security
Jul 23, 2026
CVE-2026-50517

CVE-2026-50517 is a vulnerability in Microsoft 365 Copilot where deserialization (the process of converting stored data back into usable objects) of untrusted data allows an authorized attacker to execute code over a network. This means someone with legitimate access to the system could run malicious commands remotely by sending specially crafted data to the application.

1 / 5Next
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
GitHub Advisory Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database
NVD/CVE Database

Fix: OpenAI stated it was 'continuing work on implementing a mitigation' and that the team was 'working on a fix.' Microsoft said it was 'reviewing service telemetry and diagnostic data to isolate the source of the issue,' but no specific fix or timeline was provided in the source text.

CNBC Technology
NVD/CVE Database

Microsoft Entra ID (formerly called Azure Active Directory, which manages user identities and access) has a deserialization of untrusted data vulnerability (a flaw where the software unsafely processes data from untrusted sources, allowing attackers to run malicious code). An attacker could exploit this over a network to execute code without authorization, and this vulnerability is currently being exploited by real attackers.

Fix: Apply mitigations according to Microsoft's vendor instructions while following CISA's BOD 26-04 (Prioritizing Security Updates Based on Risk) guidance. For cloud services, follow BOD 26-04 guidance for cloud environments, or discontinue use of the product if mitigations are unavailable. Organizations must evaluate their systems' internet exposure and ensure they meet BOD 26-04 patching requirements by the due date of 2026-08-24.

CISA Known Exploited Vulnerabilities
NVD/CVE Database
NVD/CVE Database

Microsoft SharePoint has a weak authentication vulnerability that allows attackers to bypass security features over a network without proper credentials. This flaw is currently being exploited by real attackers. Organizations must apply patches according to Microsoft's instructions and follow CISA's BOD 26-04 guidance (a federal directive for prioritizing security updates), or stop using the product if no fix is available.

Fix: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 guidance. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. See Microsoft Security Response Center (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040) for specific patches. Due date for patching: 2026-08-21.

CISA Known Exploited Vulnerabilities
NVD/CVE Database
NVD/CVE Database

Fix: Upgrade to the first released `Microsoft.OpenApi.Kiota` version after 1.33.0 that includes the fixes from pull requests #7910 and #7913. The fix decodes percent-encoded references before validation, rejects control characters and NUL bytes (which could truncate paths), and applies NFKC-folding (a Unicode normalization technique) to catch homoglyph bypasses. Alternatively, only generate plugins from trusted API descriptions and manually review generated manifests to ensure `response_semantics.static_template.file` values are simple relative paths within the `adaptiveCards/` folder with no `..`, rooted paths, URIs, or percent-encoded separators.

GitHub Advisory Database
NVD/CVE Database