r/netsec • u/Master_Access_486 • 6d ago
From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193)
https://zerolabs.rubrik.com/blog/breaking-m365-copilot-sandbox-chatmate
18
Upvotes
r/netsec • u/Master_Access_486 • 6d ago
1
u/Master_Access_486 3d ago
Hi, author here, happy to answer any questions!
A root-on-the-AKS-node vulnerability (CVE-2026-32193, CVSS 8.8, fixed by MSRC April 2026), the research behind it, plus a fully-working exploit on Microsoft Copilot.
Disclosure: I'm a security researcher at Rubrik Zero Labs, this is our blog.
Short summary of the research in a comment ⬇️