Prompt injection vulnerabilityEchoLeak (CVE-2025-32711): The Zero-Click Vulnerability That Reveals a Flaw in RAG-Based AI ItselfMicrosoft patched Copilot's EchoLeak flaw in May 2026, but the prompt-injection mechanism it exploited is architectural , and lives in every RAG-based AI assistant you deploy.CVE-2025-32711Microsoft 365 CopilotPrompt InjectionRAG SecurityPatch Tuesday·Jun 19, 2026·5 min readRead the story