[NEU] [hoch] Microsoft Edge: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in Microsoft Edge ausnutzen, um beliebigen Programmcode auszuführen, Daten zu manipulieren, sensible Informationen offenzulegen oder Spoofing-Angriffe durchzuführen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2643
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-658020.94% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all scored CVEs.
- Low exploitation riskCVE-2026-658040.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all scored CVEs.
- Low exploitation riskCVE-2026-663100.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-663110.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-663121.00% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all scored CVEs.
- Low exploitation riskCVE-2026-663130.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-663140.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all scored CVEs.
- Low exploitation riskCVE-2026-663150.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all scored CVEs.
- Low exploitation riskCVE-2026-663160.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-663170.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-65802 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65804 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66310 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66311 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66312 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66313 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66314 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66315 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66316 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66317 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66318 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66321 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66322 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66325 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66326 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-66326: Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to ex…nvd
- mediumCVE-2026-66325: Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized a…nvd
- highCVE-2026-66322: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- highCVE-2026-66321: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-base…nvd
- highCVE-2026-66318: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- mediumCVE-2026-66317: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- mediumCVE-2026-66316: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- highCVE-2026-66315: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute c…nvd
- mediumCVE-2026-66314: Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an…nvd
- mediumCVE-2026-66313: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- mediumCVE-2026-66312: Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute c…nvd
- mediumCVE-2026-66311: Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to pe…nvd
Recent advisories for Microsoft Edge
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-66326: Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to ex…nvd · 2026-08-04
- mediumCVE-2026-66325: Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized a…nvd · 2026-08-04
- highCVE-2026-66322: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd · 2026-08-04
- highCVE-2026-66321: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-base…nvd · 2026-08-04
- highCVE-2026-66318: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd · 2026-08-04
- mediumCVE-2026-66317: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd · 2026-08-04
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Linux Kernel: Mehrere Schwachstellen2026-08-05
- medium[NEU] [mittel] X.Org X11: Mehrere Schwachstellen ermöglichen Privilegieneskalation und Denial of Service2026-08-05
- medium[NEU] [mittel] Red Hat Ansible Automation Platform (ansible-core): Schwachstelle ermöglicht Codeausführung2026-08-05
- high[NEU] [hoch] Veeam ONE: Mehrere Schwachstellen2026-08-05
- medium[NEU] [mittel] Mozilla Firefox für Android: Schwachstelle ermöglicht Offenlegung von Informationen2026-08-05