Critical Microsoft 365 Copilot Flaws: What Organizations Need to Know

Critical Microsoft 365 Copilot Flaws: What Organizations Need to Know

Microsoft has disclosed and silently remediated three critical information-disclosure vulnerabilities in Microsoft 365 Copilot and Copilot Chat in Microsoft Edge. The flaws—CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111—were published on May 7, 2026, and Microsoft reports that mitigations were deployed on the cloud side so that no customer action or patch installation is required. While that immediate remediation reduces near-term risk, the underlying

Microsoft’s New Group Policy to Remove Windows 11 Copilot from Managed Devices

Microsoft’s New Group Policy to Remove Windows 11 Copilot from Managed Devices

Microsoft has quietly given IT teams a precise tool to remove the consumer-facing Copilot app from managed Windows 11 machines. Rolled into the April 2026 Patch Tuesday updates and bundled with Windows 11 version 25H2 (KB5083769 and later), the RemoveMicrosoftCopilotApp policy lets administrators trigger a one-time uninstall of the Copilot app on devices that meet a small set of conditions.