Multiple vulnerabilities in Microsoft Edge (July 20, 2026)
Multiple vulnerabilities have been discovered in Microsoft Edge. They allow an attacker to cause data integrity issues and an unspecified security issue by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities have been discovered that allow an attacker to cause data integrity issues and an unspecified security issue.
- Who is affected
- Users of Microsoft Edge are affected by these vulnerabilities.
- Urgency
- Remediation is necessary due to the potential for data integrity issues, though the severity is currently unknown.
- Action
- Update to the latest version of Microsoft Edge to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Edge
Get an email when a new Edge advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0903/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-159030.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-157680.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Low exploitation riskCVE-2026-157760.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all scored CVEs.
- Low exploitation riskCVE-2026-157650.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
- Low exploitation riskCVE-2026-157710.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-157750.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Low exploitation riskCVE-2026-159050.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-579800.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Low exploitation riskCVE-2026-157640.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
- Low exploitation riskCVE-2026-157690.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Google Chrome: Multiple vulnerabilities allow unspecified attackcert-bund
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- unknownDSA-6396-1 chromium - security updatedebian
- highCVE-2026-15905: Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to po…nvd
- highCVE-2026-15904: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote att…nvd
- highCVE-2026-15903: Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote a…nvd
- highCVE-2026-15902: Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to e…nvd
- criticalCVE-2026-15901: Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker t…nvd
- criticalCVE-2026-15900: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote att…nvd
- criticalCVE-2026-15899: Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remo…nvd
- medium[NEW] [medium] Microsoft Edge: Vulnerability allows bypassing security measurescert-bund
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
Recent advisories for Microsoft Edge
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Microsoft Edge for Android: Vulnerability allows disclosure and manipulation of filescert-bund · 2026-07-29
- unknownMultiple Vulnerabilities in Microsoft Edge (July 29, 2026)cert-fr-avis · 2026-07-29
- mediumCVE-2026-62828: Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to per…nvd · 2026-07-28
- medium[NEW] [medium] Microsoft Edge: Multiple vulnerabilities allow information disclosure and spoofing attackscert-bund · 2026-07-27
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert · 2026-07-27
- unknownMultiple vulnerabilities in Microsoft Edge (July 27, 2026)cert-fr-avis · 2026-07-27
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31