📍 Haddonfield, NJ 08033 Mon–Fri 9:00 AM – 6:00 PM
Home / Blog / Even Approved AI Tools Have Had Real, Serious Security Flaws This Year
Threat Intelligence

Even Approved AI Tools Have Had Real, Serious Security Flaws This Year

Between April and May 2026, researchers disclosed prompt-injection flaws in Microsoft Copilot and Salesforce Agentforce that let a single message trigger data exfiltration — no hacking required, just a well-crafted sentence.

September 8, 2026·5 min read

The “shadow AI” problem is about tools nobody approved. This one is different. It's about tools businesses did approve, from Microsoft and Salesforce, that turned out to have real vulnerabilities. If you're running Copilot or an AI agent platform and assuming the vendor has security fully handled, this year is a useful reality check.

What researchers found

In mid-April 2026, security researchers disclosed two related flaws, both since patched. The first, nicknamed “PipeLeak,” exploited public-facing lead forms in Salesforce Agentforce: a single injected instruction in a form field could trigger the AI agent to email out every available lead record. The second, “ShareLeak” (CVE-2026-21520, CVSS 7.5), worked the same way against Microsoft Copilot Studio: a crafted input in a SharePoint form connected to Copilot caused customer data to be sent to an attacker-controlled email address. Neither required special access or a traditional exploit, just an understanding of how the AI agent processes instructions embedded in ordinary-looking input.

Then on May 7, 2026, Microsoft disclosed three more information-disclosure vulnerabilities, already fully remediated server-side before the public announcement: CVE-2026-26129 in Microsoft 365 Copilot Business Chat, CVE-2026-26164 in Copilot more broadly (a network-accessible injection flaw requiring no privileges), and CVE-2026-33111 in Copilot Chat within Microsoft Edge (CVSS up to 7.5). Microsoft's own description of the risk pointed to emails, documents, Teams conversations, and confidential internal records, the kind of data these assistants are built to have broad access to in the first place.

The part worth paying attention to

With the April flaws, researchers noted that even when the platform's own safety mechanisms caught the attack attempt, data was still exfiltrated. Worth sitting with: an AI agent's built-in guardrails aren't the same thing as a security control you can rely on. The more access an assistant has to your CRM, your SharePoint, your inbox, the bigger the damage when a prompt-injection flaw like this turns up, and these tools are built to have broad access by design.

What this means if you're running Copilot or a similar AI agent

This is exactly why AI governance isn't a one-time policy document. It includes watching for vendor security advisories the same way we watch for advisories on your firewall or your email platform.

Sources

Want us to look at your setup?

Tell us what's going on and we'll quote a flat monthly number. No obligation.

Get a Free IT Review