Between April and May 2026, researchers disclosed prompt-injection flaws in Microsoft Copilot and Salesforce Agentforce that let a single message trigger data exfiltration — no hacking required, just a well-crafted sentence.
The “shadow AI” problem is about tools nobody approved. This one is different. It's about tools businesses did approve, from Microsoft and Salesforce, that turned out to have real vulnerabilities. If you're running Copilot or an AI agent platform and assuming the vendor has security fully handled, this year is a useful reality check.
In mid-April 2026, security researchers disclosed two related flaws, both since patched. The first, nicknamed “PipeLeak,” exploited public-facing lead forms in Salesforce Agentforce: a single injected instruction in a form field could trigger the AI agent to email out every available lead record. The second, “ShareLeak” (CVE-2026-21520, CVSS 7.5), worked the same way against Microsoft Copilot Studio: a crafted input in a SharePoint form connected to Copilot caused customer data to be sent to an attacker-controlled email address. Neither required special access or a traditional exploit, just an understanding of how the AI agent processes instructions embedded in ordinary-looking input.
Then on May 7, 2026, Microsoft disclosed three more information-disclosure vulnerabilities, already fully remediated server-side before the public announcement: CVE-2026-26129 in Microsoft 365 Copilot Business Chat, CVE-2026-26164 in Copilot more broadly (a network-accessible injection flaw requiring no privileges), and CVE-2026-33111 in Copilot Chat within Microsoft Edge (CVSS up to 7.5). Microsoft's own description of the risk pointed to emails, documents, Teams conversations, and confidential internal records, the kind of data these assistants are built to have broad access to in the first place.
With the April flaws, researchers noted that even when the platform's own safety mechanisms caught the attack attempt, data was still exfiltrated. Worth sitting with: an AI agent's built-in guardrails aren't the same thing as a security control you can rely on. The more access an assistant has to your CRM, your SharePoint, your inbox, the bigger the damage when a prompt-injection flaw like this turns up, and these tools are built to have broad access by design.
This is exactly why AI governance isn't a one-time policy document. It includes watching for vendor security advisories the same way we watch for advisories on your firewall or your email platform.
Tell us what's going on and we'll quote a flat monthly number. No obligation.