Multiple vulnerabilities in Microsoft Edge (July 15, 2026)
Multiple vulnerabilities have been discovered in Microsoft Edge. They allow an attacker to cause remote arbitrary code execution, privilege escalation, and an unspecified security issue by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause remote arbitrary code execution, privilege escalation, and an unspecified security issue.
- Who is affected
- Users of Microsoft Edge are affected.
- Urgency
- Remediation is urgent due to the potential for remote code execution and privilege escalation.
- Action
- Update to the latest version of Microsoft Edge.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Edge
Get an email when a new Edge advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0867/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-137910.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all scored CVEs.
- Low exploitation riskCVE-2026-143920.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all scored CVEs.
- Low exploitation riskCVE-2026-144090.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-139740.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all scored CVEs.
- Low exploitation riskCVE-2026-139140.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-141010.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-138220.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-143850.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-139490.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-582810.70% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Google Chrome: Multiple vulnerabilities allow unspecified attackcert-bund
- unknownCVE-2026-13870: Chromium: CVE-2026-13870 Use after free in WebViewmsrc
- unknownCVE-2026-14428: Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawnmsrc
- unknownCVE-2026-13827: Chromium: CVE-2026-13827 Use after free in Updatermsrc
- unknownCVE-2026-14410: Chromium: CVE-2026-14410 Inappropriate implementation in Skiamsrc
- unknownCVE-2026-13915: Chromium: CVE-2026-13915 Use after free in Chrome for iOSmsrc
- unknownCVE-2026-13923: Chromium: CVE-2026-13923 Uninitialized Use in GPUmsrc
- unknownCVE-2026-13916: Chromium: CVE-2026-13916 Inappropriate implementation in Chrome for iOSmsrc
- unknownCVE-2026-13791: Chromium: CVE-2026-13791 Insufficient validation of untrusted input in Downloadsmsrc
- unknownCVE-2026-13892: Chromium: CVE-2026-13892 Inappropriate implementation in Chrome for iOSmsrc
- unknownCVE-2026-14101: Chromium: CVE-2026-14101 Insufficient policy enforcement in Sandboxmsrc
- unknownCVE-2026-13929: Chromium: CVE-2026-13929 Insufficient validation of untrusted input in DevToolsmsrc
Recent advisories for Microsoft Edge
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Microsoft Edge for Android: Vulnerability allows disclosure and manipulation of filescert-bund · 2026-07-29
- unknownMultiple Vulnerabilities in Microsoft Edge (July 29, 2026)cert-fr-avis · 2026-07-29
- mediumCVE-2026-62828: Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to per…nvd · 2026-07-28
- medium[NEW] [medium] Microsoft Edge: Multiple vulnerabilities allow information disclosure and spoofing attackscert-bund · 2026-07-27
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert · 2026-07-27
- unknownMultiple vulnerabilities in Microsoft Edge (July 27, 2026)cert-fr-avis · 2026-07-27
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans PHP (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31