Multiple vulnerabilities in Microsoft Edge (August 21, 2026)
Multiple vulnerabilities have been discovered in Microsoft Edge. They allow an attacker to cause an unspecified security issue by the vendor.
CSIRTS triage
- What
- Multiple unspecified security issues have been discovered in Microsoft Edge.
- Who is affected
- Edge users running affected versions.
- Urgency
- Unknown severity; vendor has not disclosed details but timely updates are standard practice.
- Action
- Update Microsoft Edge to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Edge
Get an email when a new Edge advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1071/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-760410.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760440.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760430.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760340.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760350.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760380.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760400.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760330.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760450.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760370.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-76041 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76044 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76043 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76034 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76035 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76038 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76040 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76033 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76045 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76037 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76042 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76047 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Google Chrome: Multiple Vulnerabilitiescert-bund
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- unknownDSA-6455-1 chromium - security updatedebian
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Google Chrome (August 19, 2026)cert-fr-avis
- highCVE-2026-76047: Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to exe…nvd
- highCVE-2026-76045: Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to …nvd
- highCVE-2026-76044: Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who h…nvd
- highCVE-2026-76043: Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker…nvd
- lowCVE-2026-76042: Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote…nvd
- mediumCVE-2026-76041: Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to…nvd
- highCVE-2026-76040: Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote …nvd
Recent advisories for Microsoft Edge
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert · 2026-08-24
- unknownMicrosoft Edge security advisory (AV26-822)cccs · 2026-08-17
- high[NEW] [high] Microsoft Edge: Vulnerability enables code executioncert-bund · 2026-08-17
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert · 2026-08-17
- unknownMultiple vulnerabilities in Microsoft Edge (August 17, 2026)cert-fr-avis · 2026-08-17
- highCVE-2026-72970: Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker …nvd · 2026-08-14
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21