Junglewise Threat Intelligence

CVE-2026-58278: Microsoft Edge SSRF and spoofing vulnerability

CVE-2026-58278 · Severity: medium · CVSS 5.4 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge, a widely used web browser, is affected by a security flaw that could allow an attacker to trick the browser into making unauthorized network requests. This type of attack, known as spoofing, could be used to bypass certain security controls or interact with internal network resources that are not intended to be public. To be successful, an attacker would typically need to convince a user to visit a malicious website or click a specially crafted link.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48. The flaw is categorized as CWE-918 and allows an unauthenticated remote attacker to perform network spoofing. The attack requires user interaction, typically involving a victim navigating to a malicious URL. Successful exploitation allows the attacker to induce the browser to make requests to unintended destinations, potentially impacting the integrity and availability of internal or external services. Microsoft has released updates to address this vulnerability.

Affected products

  • Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48

Timeline

  • 2026-07-03: advisory: Initial publication by Microsoft and NVD

References

Related threats