Multiple vulnerabilities in Microsoft Edge (August 4, 2026)
Multiple vulnerabilities have been discovered in Microsoft Edge. They allow an attacker to cause an unspecified security issue by the publisher.
CSIRTS triage
- What
- Multiple unspecified vulnerabilities allowing an attacker to cause an unspecified security issue.
- Who is affected
- Microsoft Edge users on the August 4, 2026 release and prior versions.
- Urgency
- Moderate; multiple CVEs reported without exploitation details but advisory is recent.
- Action
- Update Microsoft Edge to the latest patched version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Edge
Get an email when a new Edge advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0967/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-179440.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-179460.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-178930.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-179070.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-178940.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-178710.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-178780.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-178860.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-179530.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-178720.07% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-17959: Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remo…nvd
- highCVE-2026-17956: Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a r…nvd
- mediumCVE-2026-17955: Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72…nvd
- mediumCVE-2026-17953: Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 …nvd
- highCVE-2026-17951: Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attack…nvd
- mediumCVE-2026-17949: Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote a…nvd
- criticalCVE-2026-17947: Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker…nvd
- mediumCVE-2026-17946: Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker wh…nvd
- mediumCVE-2026-17945: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.…nvd
- mediumCVE-2026-17944: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 …nvd
- mediumCVE-2026-17943: Inappropriate implementation in Parser in Google Chrome prior to 151.0.7922.72 allowed a remot…nvd
- mediumCVE-2026-17942: Side-channel information leakage in SVG in Google Chrome prior to 151.0.7922.72 allowed a remo…nvd
Recent advisories for Microsoft Edge
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Microsoft Edge: Multiple vulnerabilitiescert-bund · 2026-08-04
- mediumCVE-2026-66326: Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to ex…nvd · 2026-08-04
- mediumCVE-2026-66325: Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized a…nvd · 2026-08-04
- highCVE-2026-66322: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd · 2026-08-04
- highCVE-2026-66321: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-base…nvd · 2026-08-04
- highCVE-2026-66318: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd · 2026-08-04
More from CERT-FR Avis de sécurité
- unknownVulnerability in Sonicwall SonicOS (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Wallix products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Cisco products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Nextcloud products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in KeyCloak (August 6, 2026)2026-08-06