CVE-2026-24299: Microsoft 365 Copilot Memory Modification via Indirect Prompt Injection
August 18, 2026
CVE-2026-24299 is associated with research by Johann Rehberger on memory writes and deletions through indirect prompt injection in Microsoft 365 Copilot, as well as memory modification in the consumer assistant. Microsoft acknowledged the issue in a June 22 security blog post.