Tag: patched

Microsoft patched a Copilot Studio prompt injection. The data exfiltrated anyway

Microsoft has assigned CVE-2026-21520 to a CVSS 7.5 indirect prompt injection vulnerability identified in Copilot Studio. The flaw,