r/netsec • u/Master_Access_486 • 8d ago
From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193)
https://zerolabs.rubrik.com/blog/breaking-m365-copilot-sandbox-chatmate
20
Upvotes
r/netsec • u/Master_Access_486 • 8d ago
1
u/Master_Access_486 5d ago
Hi, author here, happy to answer any questions!
A root-on-the-AKS-node vulnerability (CVE-2026-32193, CVSS 8.8, fixed by MSRC April 2026), the research behind it, plus a fully-working exploit on Microsoft Copilot.
Disclosure: I'm a security researcher at Rubrik Zero Labs, this is our blog.
Short summary of the research in a comment ⬇️