Microsoft 365 Copilot customers do not appear to have a new patch to deploy after Rubrik Zero Labs’ “ChatMate” research, but the finding should change how administrators treat Copilot-connected content. The reported exploit chain moved from attacker-controlled prompt content to an interactive takeover of a victim’s Copilot chat session, then crossed into Azure infrastructure through a sandbox escape. SiliconANGLE first reported the research from Rubrik’s Black Hat USA 2026 presentation; Rubrik’s own Black Hat materials say the work covers 10 zero-day vulnerabilities across Microsoft Copilot and Azure. The crucial qualification is that the public vulnerability record does not support treating this as one newly disclosed, unpatched “Copilot flaw.” Microsoft had already published and fixed the identifiable Azure Kubernetes Service issue, CVE-2026-32193, in June. The National Vulnerability Database describes it as a path-traversal flaw in Azure Kubernetes Service that lets an authorized attacker execute code locally, and lists AKS releases before version 2026-02-13.5 as affected. CISA’s exploitation-status assessment, recorded in June, said there was no known exploitation and that the flaw was not automatable.
Rubrik researcher Ori Lahav has publicly identified CVE-2026-32193 as part of the ChatMate chain, alongside prompt injection, privilege escalation, .toml injection and an LD_PRELOAD technique. That gives the research a concrete primary-record anchor. It also exposes a gap in the headline version of the story: the public CVE says “AKS path traversal,” while the demonstrated impact is described as an AI-assistant session takeover and sandbox escape. Those are not interchangeable descriptions, and neither Microsoft nor Rubrik has publicly mapped each step of the reported 10-vulnerability chain to a complete list of CVEs.
For Windows and Microsoft 365 administrators, the event is therefore less about a missing update than a reminder that Copilot’s effective attack surface includes the files and messages it is allowed to read. A malicious document does not need to exploit a Windows endpoint if it can instead influence the assistant that searches SharePoint, OneDrive, Teams, Exchange and Microsoft Graph on behalf of an authenticated employee.

AI assistant integrating enterprise apps, automation, data governance, and cybersecurity.What “Remote Prompt Execution” means in the Copilot chain​

Rubrik calls the technique Remote Prompt Execution, or RPE. The comparison is deliberate: instead of remotely running arbitrary machine code on a victim’s computer, the attacker obtains a way to run arbitrary instructions through the victim’s AI assistant session.
In the scenario described by Rubrik, an employee uploads or asks Copilot about a document containing hostile instructions. If those instructions survive the service’s prompt-injection controls, the attacker can influence the assistant’s behavior in the user’s authenticated chat context. Rubrik says its full chain yielded interactive access to a Copilot session rather than a single forced answer, meaning the attacker could potentially keep issuing instructions through the assistant.
That matters because Copilot is useful precisely when it has broad access to a user’s working data. A user who can search a SharePoint site, summarize an Exchange thread, retrieve OneDrive files or query material through Microsoft Graph gives Copilot the same permission boundary for those tasks. In a successful session-hijack scenario, the practical question becomes what the user can access—not whether the attacker separately holds a SharePoint or Exchange credential.
SiliconANGLE quoted Rubrik Zero Labs head Joe Hladik describing a potential command-and-control outcome involving tenant files, SharePoint and OneDrive. That statement captures the potential blast radius, but it should not be read as evidence of an observed compromise of any Microsoft 365 tenant. Neither Microsoft’s public advisory record nor CISA’s assessment reports active exploitation of CVE-2026-32193, and no public technical write-up reviewed for this report identifies customers affected by ChatMate.
The direct evidence shows a responsibly disclosed research chain that Microsoft remediated. The broader concern—whether comparable paths exist in other agentic assistants—is a valid security-design issue, but it remains an inference until researchers publish reproducible technical details and vendors confirm the affected products.

The public record contradicts the reported patch timeline​

SiliconANGLE reported that Rubrik found the issue in February and that Microsoft patched it by mid-March. The most specific public record tells a more complicated story.
The NVD entry based on Microsoft’s advisory identifies CVE-2026-32193 as affecting AKS builds prior to 2026-02-13.5, which is consistent with a service-side remediation being in place by mid-February. But Microsoft’s CVE was not published until June 9, 2026, and the public advisory does not state that this CVE was patched in March, describe the Copilot chain, or name Rubrik’s research. Microsoft’s public record therefore confirms that an AKS path-traversal issue was remediated; it does not independently confirm SiliconANGLE’s February discovery and mid-March patch dates for the complete ChatMate chain.
That distinction is worth making because the chronology changes the operational interpretation. A flaw remediated in a Microsoft-hosted service in February does not create a fresh emergency for Microsoft 365 tenants in August. A flaw only publicly described in June can still matter for retrospective investigation, threat modeling and supplier assurance, but it is not automatically a reason to assume an exposed production window remains open.
The current public evidence also does not establish that CVE-2026-32193 alone enabled the claimed session takeover. Lahav’s own description presents it as a chain containing multiple elements. Rubrik says 10 Microsoft Copilot and Azure zero-days were involved, yet it has not published a corresponding 10-CVE list. Until it does, security teams should avoid falsely narrowing the issue to one AKS CVE—or falsely inflating one AKS CVE into proof that every Copilot deployment was remotely compromisable.

Copilot’s hosted-service model limits the patching task​

Microsoft 365 Copilot is an online service. Customers generally do not apply a monthly Windows update or Office build update to remediate a backend Copilot flaw. Microsoft controls the service deployment, while tenants control identity, data access, auditing and the content paths that feed the assistant.
This case makes that division of responsibility unusually visible. The relevant technical components span Copilot, Azure infrastructure and the data sources Copilot can reach. Endpoint patch compliance remains necessary, particularly for Microsoft Edge and Office, but it is not a substitute for checking whether Copilot can index sensitive repositories or act on data that ordinary users have accumulated access to over years.
Microsoft’s June security disclosures underscore the point. The same month’s public advisories included CVE-2026-42824, an M365 Copilot information-disclosure issue involving command injection, and CVE-2026-47644, an information-disclosure vulnerability in Copilot Chat in Microsoft Edge. Independent patch analyses from CrowdStrike and BleepingComputer listed a separate Microsoft 365 Copilot remote-code-execution advisory, CVE-2026-45497, as well. Those disclosures should not be casually folded into ChatMate—the public materials do not demonstrate they are the same chain—but they show that Copilot’s data-handling and output-handling boundaries are now a recurring security category rather than a one-off research novelty.
For AKS operators, CVE-2026-32193 requires a different check. The NVD record says releases earlier than 2026-02-13.5 were affected. Teams running Azure Kubernetes Service should verify that their service and cluster maintenance posture aligns with Microsoft’s remediated release path, rather than assuming Copilot licensing or Microsoft 365 update status says anything about AKS exposure.

The immediate defensive work is data and identity hygiene​

The strongest practical response is to reduce what a compromised or manipulated assistant could retrieve. Copilot does not create pre-existing SharePoint, OneDrive or Exchange permissions, but it can make overbroad permissions easier to discover and query at scale. That makes stale sharing links, broadly accessible team sites and unmanaged sensitive repositories more consequential after deployment.
Administrators should treat externally sourced documents, email and shared links as potentially hostile instructions, not merely potentially hostile attachments. Traditional malware controls inspect whether a file executes code on the endpoint. AI-assisted workflows need another control question: whether the content will be retrieved, summarized or acted on by a model with access to internal systems.
A focused review should include the following work:
  • Review Copilot retrieval sources and restrict the assistant from indexing repositories that hold regulated, privileged or business-critical content unless the access model has been validated.
  • Use Microsoft Purview sensitivity labels, data-loss-prevention controls and restricted SharePoint search or discovery settings to reduce the material discoverable through a compromised user session.
  • Audit SharePoint and OneDrive sharing permissions, especially “Everyone except external users,” broad group memberships, inherited access and old project sites that remain searchable long after a project closes.
  • Ensure Copilot activity, Microsoft Graph access and abnormal SharePoint or OneDrive retrieval patterns are retained in logs that the security operations team can investigate.
  • Revisit conditional access and phishing-resistant multifactor authentication for accounts with broad Microsoft 365 access, because an assistant inherits the authority of the session and identity behind it.
Rubrik’s survey claim that only 23% of security leaders have full visibility into AI agents is its own research, not an independently established measurement of enterprise conditions. Still, the operational premise is difficult to dispute: many organizations have deployed Copilot capabilities before establishing a complete inventory of agents, connectors, data sources and delegated permissions.

The missing details are now the security story​

Rubrik has substantiated that ChatMate was a real Black Hat presentation and has linked at least one component to CVE-2026-32193. Microsoft’s public advisory record substantiates that the AKS component was fixed, with no known exploitation reported by CISA. What remains undisclosed is the information that would let customers accurately measure historical risk: the full CVE mapping, the exact vulnerable service builds, whether any customer telemetry indicated exploitation, and which Copilot product boundaries were involved at each stage.
That absence should temper both complacency and alarm. There is no evidence in the public record that administrators must take emergency action to patch Microsoft 365 Copilot today. There is also no basis for treating Copilot’s existing service-side fixes as a complete answer to document-borne prompt injection and over-permissioned enterprise data.
The concrete consequence is that Copilot security reviews can no longer stop at licensing, endpoint updates and acceptable-use policy. They need to include the content Copilot consumes, the permissions it inherits, and the monitoring that would reveal an assistant behaving as an attacker’s proxy.

References​

  1. Primary source: SiliconANGLE
    Published: 2026-08-06T23:04:36+00:00
  2. Related coverage: rubrik.com
  3. Related coverage: docs.github.com
  4. Related coverage: rubrik.com
  5. Related coverage: microsoft.com
  6. Related coverage: nvd.nist.gov
  7. Related coverage: cert.ssi.gouv.fr
  8. Related coverage: nvd.nist.gov
  9. Related coverage: bleepingcomputer.com
  10. Related coverage: windowsforum.com
  11. Related coverage: aisecuritywire.com
  12. Related coverage: cloudsecurityalliance.org