[NEW] [high] Microsoft Edge: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Microsoft Edge to execute arbitrary code, manipulate data, disclose sensitive information, or perform spoofing attacks.
CSIRTS triage
- What
- Multiple vulnerabilities allowing remote anonymous attackers to bypass security, manipulate data, and disclose confidential information.
- Who is affected
- Deployments of IBM App Connect Enterprise vulnerable to remote exploitation without authentication.
- Urgency
- Patch promptly as multiple security bypasses and information disclosure vulnerabilities enable further compromise.
- Action
- Apply security updates from IBM for App Connect Enterprise to address CVE-2026-42033 through CVE-2026-42040.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch App Connect Enterprise
Get an email when a new App Connect Enterprise advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2643
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-658020.94% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-658040.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-663100.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-663110.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-663121.00% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-663130.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-663140.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-663150.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-663160.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-663170.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-65802 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65804 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66310 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66311 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66312 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66313 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66314 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66315 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66316 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66317 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66318 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66321 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66322 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66325 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66326 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-66326: Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to ex…nvd
- mediumCVE-2026-66325: Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized a…nvd
- highCVE-2026-66322: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- highCVE-2026-66321: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-base…nvd
- highCVE-2026-66318: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- mediumCVE-2026-66317: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- mediumCVE-2026-66316: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- highCVE-2026-66315: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute c…nvd
- mediumCVE-2026-66314: Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an…nvd
- mediumCVE-2026-66313: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd
- mediumCVE-2026-66312: Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute c…nvd
- mediumCVE-2026-66311: Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to pe…nvd
Recent advisories for Microsoft Edge
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-66326: Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to ex…nvd · 2026-08-04
- mediumCVE-2026-66325: Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized a…nvd · 2026-08-04
- highCVE-2026-66322: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd · 2026-08-04
- highCVE-2026-66321: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-base…nvd · 2026-08-04
- highCVE-2026-66318: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd · 2026-08-04
- mediumCVE-2026-66317: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to …nvd · 2026-08-04
More from CERT-Bund (BSI) Security Advisories
- medium[NEW] [medium] Apache CXF: Multiple Vulnerabilities2026-08-07
- medium[NEW] [medium] X.Org X11 Server (libXfont2): Multiple vulnerabilities allow execution of arbitrary code with a…2026-08-06
- high[UPDATE] [high] WSO2 API Manager: Multiple vulnerabilities2026-08-06
- medium[NEW] [medium] Red Hat OpenShift Container Platform (fast-uri, OpenTelemetry-Go): Multiple vulnerabilities2026-08-06
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …2026-08-06