Multiple Vulnerabilities in Microsoft Edge (July 29, 2026)
Multiple vulnerabilities have been discovered in Microsoft Edge. They allow an attacker to cause data integrity issues and an unspecified security issue by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities cause data integrity issues and unspecified security issues.
- Who is affected
- Users of Microsoft Edge are affected.
- Urgency
- Remediation is necessary due to potential data integrity issues.
- Action
- Apply patches as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Edge
Get an email when a new Edge advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0943/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-151180.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-628280.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-132820.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-151250.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-151300.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-151200.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2026-151120.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-151150.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-151210.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-151240.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Microsoft Edge for Android: Vulnerability allows disclosure and manipulation of filescert-bund
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-62828: Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to per…nvd
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownDSA-6390-1 chromium - security updatedebian
- unknownMultiple vulnerabilities in Google Chrome (July 15, 2026)cert-fr-avis
- highCVE-2026-15767: Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a r…nvd
- mediumCVE-2026-62828: Microsoft Edge for Android (Chromium-based) Tampering Vulnerabilitymsrc
- unknownCVE-2026-15126: Chromium: CVE-2026-15126 Use after free in Formsmsrc
- unknownCVE-2026-15107: Chromium: CVE-2026-15107 Use after free in IndexedDBmsrc
Recent advisories for Microsoft Edge
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Microsoft Edge for Android: Vulnerability allows disclosure and manipulation of filescert-bund · 2026-07-29
- mediumCVE-2026-62828: Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to per…nvd · 2026-07-28
- medium[NEW] [medium] Microsoft Edge: Multiple vulnerabilities allow information disclosure and spoofing attackscert-bund · 2026-07-27
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert · 2026-07-27
- unknownMultiple vulnerabilities in Microsoft Edge (July 27, 2026)cert-fr-avis · 2026-07-27
- highCVE-2026-57990: Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows …nvd · 2026-07-26
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31