Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-78905

Type confusion in ANGLE in Microsoft Edge vulnerability

Type confusion in ANGLE in Microsoft Edge vulnerability (CVE-2026-78905) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78904

Type confusion in ANGLE in Microsoft Edge vulnerability

Type confusion in ANGLE in Microsoft Edge vulnerability (CVE-2026-78904) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78903

Incomplete cleanup in SiteIsolation in Microsoft Edge vulnerability

Incomplete cleanup in SiteIsolation in Microsoft Edge vulnerability (CVE-2026-78903) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78901

Race condition in V8 in Microsoft Edge vulnerability

Race condition in V8 in Microsoft Edge vulnerability (CVE-2026-78901) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78900

Improper input validation in Media in Microsoft Edge vulnerability

Improper input validation in Media in Microsoft Edge vulnerability (CVE-2026-78900) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78899

Use after free in V8 in Microsoft Edge vulnerability

Use after free in V8 in Microsoft Edge vulnerability (CVE-2026-78899) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78898

Incorrect authorization in Downloads in Microsoft Edge vulnerability

Incorrect authorization in Downloads in Microsoft Edge vulnerability (CVE-2026-78898) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78897

Missing authorization in BrowserTag in Microsoft Edge vulnerability

Missing authorization in BrowserTag in Microsoft Edge vulnerability (CVE-2026-78897) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78896

Information leak in StorageAccessAPI in Microsoft Edge vulnerability

Information leak in StorageAccessAPI in Microsoft Edge vulnerability (CVE-2026-78896) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78895

Information leak in Paint in Microsoft Edge vulnerability

Information leak in Paint in Microsoft Edge vulnerability (CVE-2026-78895) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78894

Race condition in Payments in Microsoft Edge vulnerability

Race condition in Payments in Microsoft Edge vulnerability (CVE-2026-78894) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78893

Information leak in QUIC in Microsoft Edge vulnerability

Information leak in QUIC in Microsoft Edge vulnerability (CVE-2026-78893) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78892

Incorrect authorization in Chromoting in Microsoft Edge vulnerability

Incorrect authorization in Chromoting in Microsoft Edge vulnerability (CVE-2026-78892) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78891

Buffer overflow in WebRTC in Microsoft Edge vulnerability

Buffer overflow in WebRTC in Microsoft Edge vulnerability (CVE-2026-78891) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72984

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-72984) was added to Microsoft’s security update guidance. <p>Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-70341

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-70341) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-70331

Microsoft Edge for iOS Spoofing vulnerability

Microsoft Edge for iOS Spoofing vulnerability (CVE-2026-70331) was added to Microsoft’s security update guidance. <p>Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-70309

Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability

Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability (CVE-2026-70309) was added to Microsoft’s security update guidance. <p>Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66798

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-66798) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66324

Microsoft Edge (Chromium-based) Spoofing vulnerability

Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-66324) was added to Microsoft’s security update guidance. <p>External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66323

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-66323) was added to Microsoft’s security update guidance. <p>Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65813

Microsoft Exchange Server Elevation of Privilege vulnerability

Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-65813) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62904

Microsoft Edge (Chromium-based) Information Disclosure vulnerability

Microsoft Edge (Chromium-based) Information Disclosure vulnerability (CVE-2026-62904) was added to Microsoft’s security update guidance. <p>Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-70329

Microsoft Outlook Remote Code Execution vulnerability

Microsoft Outlook Remote Code Execution vulnerability (CVE-2026-70329) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.