Multiple vulnerabilities in Microsoft Edge (August 3, 2026)
Multiple vulnerabilities have been discovered in Microsoft Edge. Some of them allow an attacker to cause remote arbitrary code execution, data confidentiality breach and data integrity breach.
CSIRTS triage
- What
- Microsoft Edge contains multiple vulnerabilities including remote code execution, confidentiality breaches, and integrity violations.
- Who is affected
- All Edge browser users with affected versions are at risk.
- Urgency
- Critical; RCE and data breach vulnerabilities present severe exploitation risk.
- Action
- Update Microsoft Edge to the patched version released August 3, 2026 immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Edge
Get an email when a new Edge advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0960/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-179830.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-176700.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-176960.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-179880.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-177500.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-180010.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-180130.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-177310.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-178230.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-178600.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Microsoft Edge: Multiple vulnerabilitiescert-bund
- highCVE-2026-66310: External control of file name or path in Microsoft Edge for Android allows an unauthorized att…nvd
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- unknownDSA-6408-1 chromium - security updatedebian
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- criticalCVE-2026-18015: Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a …nvd
- mediumCVE-2026-18013: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 …nvd
- mediumCVE-2026-18007: Inappropriate implementation in Input in Google Chrome on Android prior to 151.0.7922.72 allow…nvd
- mediumCVE-2026-18006: Inappropriate implementation in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a …nvd
- mediumCVE-2026-18004: Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a re…nvd
- mediumCVE-2026-18003: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 …nvd
Recent advisories for Microsoft Edge
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert · 2026-08-24
- unknownMultiple vulnerabilities in Microsoft Edge (August 21, 2026)cert-fr-avis · 2026-08-21
- unknownMicrosoft Edge security advisory (AV26-822)cccs · 2026-08-17
- high[NEW] [high] Microsoft Edge: Vulnerability enables code executioncert-bund · 2026-08-17
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert · 2026-08-17
- unknownMultiple vulnerabilities in Microsoft Edge (August 17, 2026)cert-fr-avis · 2026-08-17
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21