Multiples vulnérabilités dans Microsoft Edge (15 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une élévation de privilèges et un problème de sécurité non spécifié par l'éditeur.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1173/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-876460.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874450.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-876190.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-875670.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-875410.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-875010.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-876260.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-876560.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-874760.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-876220.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Google Chrome / Microsoft Edge: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angrif…cert-bund
- unknownexploitedGoogle Chrome Multiple Vulnerabilitieshkcert
- mediumCVE-2026-87658: Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attack…nvd
- lowCVE-2026-87657: Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had…nvd
- mediumCVE-2026-87656: Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a re…nvd
- criticalCVE-2026-87654: Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remot…nvd
- mediumCVE-2026-87653: UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allow…nvd
- lowCVE-2026-87652: Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote at…nvd
- criticalCVE-2026-87650: Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker …nvd
- criticalCVE-2026-87646: Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote …nvd
- highCVE-2026-87639: Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attack…nvd
- mediumCVE-2026-87635: UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote atta…nvd
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans les produits Apple (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans les produits Cisco (15 septembre 2026)2026-09-15
- unknownVulnérabilité dans Microsoft Windows (15 septembre 2026)2026-09-15
- unknownMultiples vulnérabilités dans Squid (14 septembre 2026)2026-09-14
- unknownMultiples vulnérabilités dans MongoDB (14 septembre 2026)2026-09-14