Information Disclosure Vulnerability in Microsoft Word Copilot
CVE-2026-21521
7.4HIGH
What is CVE-2026-21521?
An information disclosure vulnerability exists in Microsoft Word Copilot due to improper neutralization of escape, meta, or control sequences. This flaw could be exploited by an unauthorized attacker to reveal sensitive information across a network, potentially compromising the confidentiality of user data. It is essential for users and organizations to apply the necessary patches and updates to mitigate the risk associated with this vulnerability.
Affected Version(s)
Microsoft 365 Word Copilot -