Microsoft disclosed a critical improper-authorization vulnerability (CVSS 9.3) in Copilot Cowork, the AI collaboration agent within the Microsoft 365 Copilot family. The flaw could have let an attacker elevate privileges over a network and gain unauthorized access to organizational content, though exploitation required some user interaction. Microsoft patched the flaw as part of its August 2026 Patch Tuesday release and reported no evidence of active exploitation.