
Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway.
Did you hear about Microsoft assigning CVE-2026-21520 to Copilot Studio for a CVSS 7.5 indirect prompt injection vulnerability? It was discovered by Capsule Security, disclosed to Microsoft, and patched on […]







