Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-13822

Inappropriate implementation in Extensions in Microsoft Edge vulnerability

Inappropriate implementation in Extensions in Microsoft Edge vulnerability (CVE-2026-13822) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13819

Out of bounds read in ANGLE in Microsoft Edge vulnerability

Out of bounds read in ANGLE in Microsoft Edge vulnerability (CVE-2026-13819) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13816

Insufficient validation of untrusted input in File Input in Microsoft Edge vulnerability

Insufficient validation of untrusted input in File Input in Microsoft Edge vulnerability (CVE-2026-13816) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13813

Insufficient validation of untrusted input in Chrome for iOS in Microsoft Edge vulnerability

Insufficient validation of untrusted input in Chrome for iOS in Microsoft Edge vulnerability (CVE-2026-13813) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13812

Insufficient validation of untrusted input in Chrome for iOS in Microsoft Edge vulnerability

Insufficient validation of untrusted input in Chrome for iOS in Microsoft Edge vulnerability (CVE-2026-13812) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13809

Side-channel information leakage in Safe Browsing in Microsoft Edge vulnerability

Side-channel information leakage in Safe Browsing in Microsoft Edge vulnerability (CVE-2026-13809) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13808

Insufficient data validation in Chrome for iOS in Microsoft Edge vulnerability

Insufficient data validation in Chrome for iOS in Microsoft Edge vulnerability (CVE-2026-13808) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13807

Use after free in Import in Microsoft Edge vulnerability

Use after free in Import in Microsoft Edge vulnerability (CVE-2026-13807) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13805

Use after free in GFX in Microsoft Edge vulnerability

Use after free in GFX in Microsoft Edge vulnerability (CVE-2026-13805) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13795

Insufficient policy enforcement in Chrome for iOS in Microsoft Edge vulnerability

Insufficient policy enforcement in Chrome for iOS in Microsoft Edge vulnerability (CVE-2026-13795) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13792

Use after free in Touchbar in Microsoft Edge vulnerability

Use after free in Touchbar in Microsoft Edge vulnerability (CVE-2026-13792) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13791

Insufficient validation of untrusted input in Downloads in Microsoft Edge vulnerability

Insufficient validation of untrusted input in Downloads in Microsoft Edge vulnerability (CVE-2026-13791) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13788

Use after free in Fullscreen in Microsoft Edge vulnerability

Use after free in Fullscreen in Microsoft Edge vulnerability (CVE-2026-13788) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13785

Use after free in Bluetooth in Microsoft Edge vulnerability

Use after free in Bluetooth in Microsoft Edge vulnerability (CVE-2026-13785) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13778

Use after free in WebUSB in Microsoft Edge vulnerability

Use after free in WebUSB in Microsoft Edge vulnerability (CVE-2026-13778) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13777

Insufficient validation of untrusted input in iOSWeb in Microsoft Edge vulnerability

Insufficient validation of untrusted input in iOSWeb in Microsoft Edge vulnerability (CVE-2026-13777) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58525

Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability

Microsoft Edge (Chromium-based) Security Feature Bypass vulnerability (CVE-2026-58525) was added to Microsoft’s security update guidance. Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50656

Microsoft Defender Elevation of Privilege vulnerability

Microsoft Defender Elevation of Privilege vulnerability (CVE-2026-50656) was added to Microsoft’s security update guidance. Microsoft has released an update to the Microsoft Malware Protection Engine that addresses the vulnerability identified by CVE-2026-50656. Please see the FAQ for more information on how to check if the new version has been installed. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58597

Microsoft Edge (Chromium-based) Spoofing vulnerability

Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-58597) was added to Microsoft’s security update guidance. Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58524

Microsoft Edge (Chromium-based) Spoofing vulnerability

Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-58524) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58523

Microsoft Edge for Android Security Feature Bypass vulnerability

Microsoft Edge for Android Security Feature Bypass vulnerability (CVE-2026-58523) was added to Microsoft’s security update guidance. Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58522

Microsoft Edge for Android Information Disclosure vulnerability

Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58522) was added to Microsoft’s security update guidance. Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58300

Microsoft Edge for Android Information Disclosure vulnerability

Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58300) was added to Microsoft’s security update guidance. Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58299

Microsoft Edge for Android Remote Code Execution vulnerability

Microsoft Edge for Android Remote Code Execution vulnerability (CVE-2026-58299) was added to Microsoft’s security update guidance. Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.