Microsoft Edge

15 known vulnerabilities in Microsoft Edge, 2 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2021-26411 CVSS 8.8 high · actively exploited Microsoft Internet Explorer Memory Corruption Vulnerability
  • CVE-2020-0878 CVSS 4.2 medium · actively exploited Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

Latest vulnerabilities

  • CVE-2026-88097 CVSS 7.8 high Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
  • CVE-2026-85893 CVSS 8.8 high Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
  • CVE-2026-69486 CVSS 8.8 high Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
  • CVE-2026-85892 CVSS 7.8 high Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an…
  • CVE-2026-77490 CVSS 6.1 medium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an…
  • CVE-2026-70341 CVSS 8.5 high Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
  • CVE-2026-72984 CVSS 8.8 high Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to…
  • CVE-2026-70331 CVSS 5.4 medium Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over…
  • CVE-2026-70309 CVSS 5.4 medium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
  • CVE-2026-66798 CVSS 4.3 medium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
  • CVE-2026-62904 CVSS 5.4 medium Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
  • CVE-2026-58616 CVSS 3.0 low Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an…
  • CVE-2026-55945 CVSS 4.2 medium Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an…
  • CVE-2021-26411 CVSS 8.8 high · actively exploited Microsoft Internet Explorer Memory Corruption Vulnerability
  • CVE-2020-0878 CVSS 4.2 medium · actively exploited Microsoft Edge and Internet Explorer Memory Corruption Vulnerability