Multiple vulnerabilities in Microsoft Edge (August 17, 2026)
Multiple vulnerabilities have been discovered in Microsoft Edge. They allow an attacker to cause remote arbitrary code execution and an unspecified security issue by the publisher.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Edge allow remote arbitrary code execution and an unspecified security issue.
- Who is affected
- All users of Microsoft Edge are affected.
- Urgency
- Patch without delay; remote code execution vulnerabilities in browsers pose immediate risk to all users.
- Action
- Update Microsoft Edge to the latest version containing the security fixes.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Edge
Get an email when a new Edge advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1034/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-195560.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-195600.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-729700.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-195590.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-195580.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-195570.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19556 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19560 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-72970 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19559 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19558 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19557 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMicrosoft Edge security advisory (AV26-822)cccs
- high[NEW] [high] Google Chrome: Multiple Vulnerabilities Enable Unspecified Attackcert-bund
- high[NEW] [high] Microsoft Edge: Vulnerability enables code executioncert-bund
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- highCVE-2026-72970: Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker …nvd
- unknownDSA-6436-1 chromium - security updatedebian
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Google Chrome (August 12, 2026)cert-fr-avis
- highCVE-2026-19560: Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to …nvd
- highCVE-2026-19559: Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to e…nvd
- highCVE-2026-19558: Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who …nvd
- highCVE-2026-19557: Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote at…nvd
Recent advisories for Microsoft Edge
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert · 2026-08-24
- unknownMultiple vulnerabilities in Microsoft Edge (August 21, 2026)cert-fr-avis · 2026-08-21
- unknownMicrosoft Edge security advisory (AV26-822)cccs · 2026-08-17
- high[NEW] [high] Microsoft Edge: Vulnerability enables code executioncert-bund · 2026-08-17
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert · 2026-08-17
- highCVE-2026-72970: Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker …nvd · 2026-08-14
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21