Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-57985

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-57985) was added to Microsoft’s security update guidance. Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57984

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-57984) was added to Microsoft’s security update guidance. Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57983

Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability

Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability (CVE-2026-57983) was added to Microsoft’s security update guidance. Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57981

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-57981) was added to Microsoft’s security update guidance. Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57977

Microsoft Edge (Chromium-based) Spoofing vulnerability

Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-57977) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57975

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-57975) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57974

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-57974) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56646

Microsoft Edge (Chromium-based) Spoofing vulnerability

Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-56646) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56645

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-56645) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55945

Microsoft Edge (Chromium-based) Information Disclosure vulnerability

Microsoft Edge (Chromium-based) Information Disclosure vulnerability (CVE-2026-55945) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45488

Microsoft Edge (Chromium-based) Spoofing vulnerability

Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-45488) was added to Microsoft’s security update guidance. User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14156

Policy bypass in StorageAccessAPI in Microsoft Edge vulnerability

Policy bypass in StorageAccessAPI in Microsoft Edge vulnerability (CVE-2026-14156) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14155

Insufficient policy enforcement in StorageAccessAPI in Microsoft Edge vulnerability

Insufficient policy enforcement in StorageAccessAPI in Microsoft Edge vulnerability (CVE-2026-14155) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14154

Inappropriate implementation in DevTools in Microsoft Edge vulnerability

Inappropriate implementation in DevTools in Microsoft Edge vulnerability (CVE-2026-14154) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14153

Inappropriate implementation in Glic in Microsoft Edge vulnerability

Inappropriate implementation in Glic in Microsoft Edge vulnerability (CVE-2026-14153) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14152

Out of bounds write in ANGLE in Microsoft Edge vulnerability

Out of bounds write in ANGLE in Microsoft Edge vulnerability (CVE-2026-14152) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14151

Inappropriate implementation in AI in Microsoft Edge vulnerability

Inappropriate implementation in AI in Microsoft Edge vulnerability (CVE-2026-14151) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14150

Insufficient validation of untrusted input in Speech in Microsoft Edge vulnerability

Insufficient validation of untrusted input in Speech in Microsoft Edge vulnerability (CVE-2026-14150) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14149

Use after free in Audio in Microsoft Edge vulnerability

Use after free in Audio in Microsoft Edge vulnerability (CVE-2026-14149) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14148

Type Confusion in CSS in Microsoft Edge vulnerability

Type Confusion in CSS in Microsoft Edge vulnerability (CVE-2026-14148) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14147

Inappropriate implementation in CSS in Microsoft Edge vulnerability

Inappropriate implementation in CSS in Microsoft Edge vulnerability (CVE-2026-14147) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14146

Inappropriate implementation in CSS in Microsoft Edge vulnerability

Inappropriate implementation in CSS in Microsoft Edge vulnerability (CVE-2026-14146) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14145

Inappropriate implementation in CSS in Microsoft Edge vulnerability

Inappropriate implementation in CSS in Microsoft Edge vulnerability (CVE-2026-14145) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-14144

Incorrect security UI in Views in Microsoft Edge vulnerability

Incorrect security UI in Views in Microsoft Edge vulnerability (CVE-2026-14144) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.