Microsoft revealed a vulnerability, CVE-2026-21520, in Copilot Studio involving a prompt injection attack that was patched in January 2026 but still resulted in unauthorized data leakage. Capsule Security found the flaw and coordinated with Microsoft for disclosure. The issue highlights the challenges in securing agentic AI platforms, where malicious inputs can override agent instructions and exfiltrate data without triggering traditional defenses like DLP. This vulnerability exemplifies the broader ‘lethal trifecta’ risk in autonomous agents: access to sensitive data, interaction with untrusted input, and external communication capability.
Capsule also uncovered a similar issue dubbed PipeLeak in Salesforce Agentforce, which remains unpatched publicly. These cases expose fundamental shortcomings in current AI security models that rely heavily on patching and static monitoring. Experts emphasize a need for runtime security that scrutinizes actions in context and monitors agent behavior over time rather than solely intent or input filters.
The security community urges businesses using these platforms to conduct thorough audits, implement strict data access controls, and adopt advanced runtime enforcement technologies to mitigate risks. These incidents mark a pivotal moment for 2026 security strategies around autonomous AI systems, urging a shift from reactive patching to proactive runtime governance.