記事一覧に戻る

Microsoft's patched Copilot Studio vulnerability signals a new security challenge for enterprise AI agents that patches alone cannot fully eliminate.

VentureBeat AI · 2026年4月15日

Microsoft's patched Copilot Studio vulnerability signals a new security challenge for enterprise AI agents that patches alone cannot fully eliminate.

AI要約

  • Microsoft assigned CVE-2026-21520 (CVSS 7.5) to an indirect prompt injection flaw in Copilot Studio discovered by Capsule Security, with the patch deployed January 15, 2026.
  • The CVE assignment is unusual because it marks the first time Microsoft has formally recognized a prompt injection vulnerability in an agentic platform—previously only assigning CVE-2025-32711 to M365 Copilot's EchoLeak.
  • Prompt injection vulnerabilities in agent-building platforms represent a new vulnerability class that enterprises cannot fully eliminate through patches alone, raising ongoing security concerns.
  • Capsule Security also discovered PipeLeak, a parallel indirect prompt injection vulnerability affecting Salesforce Agentforce, suggesting the issue extends beyond Microsoft's ecosystem.

関連記事

AIニュースを毎日お届け

200以上のソースから厳選したAIニュースを毎日無料でお届けします。

無料で始める