4 min read
News Brief A critical improper-authorization flaw in Microsoft Copilot Cowork, tracked as CVE-2026-59118 and scoring 9.3, let attackers elevate privileges over the network. Microsoft fixed it in the August 2026 Patch Tuesday round, roughly two months after the agent went GA.