Multiple vulnerabilities in Microsoft Edge (July 27, 2026)
Multiple vulnerabilities have been discovered in Microsoft Edge. They allow an attacker to cause data privacy issues, bypass the security policy, and an unspecified security issue by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Edge can cause data privacy issues and allow security policy bypass.
- Who is affected
- Users of Microsoft Edge.
- Urgency
- Remediation is high urgency due to the potential for exploitation and the impact on user privacy.
- Action
- Update Microsoft Edge to the latest version to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Microsoft Edge
Get an email when a new Microsoft Edge advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0937/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-168070.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-168040.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-168060.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-579900.94% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all scored CVEs.
- Low exploitation riskCVE-2026-579890.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-168050.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-579780.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16807 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16804 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16806 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57990 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57989 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16805 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57978 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownDSA-6408-1 chromium - security updatedebian
- high[NEW] [high] Google Chrome: Multiple vulnerabilities allow unspecified attackcert-bund
- unknownMicrosoft security advisory (AV26-747)cccs
- medium[NEW] [medium] Microsoft Edge: Multiple vulnerabilities allow information disclosure and spoofing attackscert-bund
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- highCVE-2026-57990: Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows …nvd
- highCVE-2026-57989: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- mediumCVE-2026-57978: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Google Chrome (July 24, 2026)cert-fr-avis
- highCVE-2026-16807: Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attack…nvd
- highCVE-2026-16806: Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to…nvd
Recent advisories for Microsoft Edge
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Microsoft Edge for Android: Vulnerability allows disclosure and manipulation of filescert-bund · 2026-07-29
- unknownMultiple Vulnerabilities in Microsoft Edge (July 29, 2026)cert-fr-avis · 2026-07-29
- mediumCVE-2026-62828: Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to per…nvd · 2026-07-28
- medium[NEW] [medium] Microsoft Edge: Multiple vulnerabilities allow information disclosure and spoofing attackscert-bund · 2026-07-27
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert · 2026-07-27
- highCVE-2026-57990: Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows …nvd · 2026-07-26
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31