Multiple vulnerabilities in Microsoft Edge (August 12, 2026)
Multiple vulnerabilities have been discovered in Microsoft Edge. They allow an attacker to cause remote arbitrary code execution and a security issue not specified by the publisher.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Edge enable remote code execution and unspecified security issues.
- Who is affected
- Microsoft Edge browser users on all platforms affected by the listed CVEs.
- Urgency
- Highly urgent; browser RCE vulnerabilities enable arbitrary code execution in client environments.
- Action
- Update Microsoft Edge to the latest patched version immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Edge
Get an email when a new Edge advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0999/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-191650.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-191550.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-191500.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-191570.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-191560.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-191610.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-191710.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-703390.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-191380.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-191450.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Microsoft Edge: Vulnerability Enables Code Executioncert-bund
- mediumCVE-2026-70339: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-base…nvd
- mediumCVE-2026-70339: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerabilitymsrc
- unknownCVE-2026-19157: CVE-2026-19157 Out of bounds write in ANGLEmsrc
- unknownCVE-2026-19137: CVE-2026-19137 Use after free in WebGLmsrc
- unknownCVE-2026-19138: CVE-2026-19138 Heap buffer overflow in CrashReportingmsrc
- unknownCVE-2026-19146: CVE-2026-19146 Uninitialized Use in GPUmsrc
- unknownCVE-2026-19152: CVE-2026-19152 Inappropriate implementation in Navigationmsrc
- unknownCVE-2026-19162: CVE-2026-19162 Out of bounds write in V8msrc
- unknownCVE-2026-19175: CVE-2026-19175 Use after free in Paymentsmsrc
- unknownCVE-2026-19144: CVE-2026-19144 Use after free in HTMLmsrc
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Debian Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Elastic Kibana (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Netgate products (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in SUSE Linux kernel (August 14, 2026)2026-08-14
- unknownVulnerability in Sophos products (August 14, 2026)2026-08-14