Microsoft fixed a defect in Classic Outlook for Windows that caused Copilot Chat and other Copilot entry points to disappear for users with the Copilot Chat (Basic) license after updating to builds 16.0.20026.20182 and later. The issue affected the Outlook interface only and did not impact customers with the full Microsoft 365 Copilot license, pointing to a licensing-validation problem in the desktop client rather than a broader Copilot service outage. Microsoft said the Outlook team resolved the problem through a server-side service change and told affected users to restart Outlook or update to the latest build if the buttons did not immediately return.
During the disruption, Copilot remained accessible through Outlook on the web, new Outlook, and the standalone Microsoft 365 Copilot app or web experience, while Microsoft also suggested reverting to build 16.0.20026.20168 as a fallback. Separately, Microsoft said it is investigating another Outlook problem that causes crashes on systems running Kaspersky Antivirus, tied to the Mail Checker module mcou.dll; affected users were advised to review Application log Event 1000 entries showing OUTLOOK.EXE and MCOU.DLL and to contact Kaspersky support.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
After updating Classic Outlook for Windows to build 20026.20182 and later, users with the Copilot Chat (Basic) license lost Copilot Chat and Copilot entry points in the interface. Microsoft said the issue did not affect users with the full Microsoft 365 Copilot paid license.
Microsoft is investigating a separate issue causing Outlook crashes on systems running Kaspersky Antivirus. The company linked the crashes to the Kaspersky Mail Checker module mcou.dll and advised users to verify the problem through Application log Event 1000 entries showing OUTLOOK.EXE and MCOU.DLL before contacting Kaspersky support.
Microsoft said the Outlook team fixed the problem through a service-side change on June 29, 2026. Affected users were advised to restart Outlook, with fallback workarounds including using new Outlook or Outlook Web Access and reverting to build 16.0.20026.20168.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcesupport.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.