Junglewise Threat Intelligence

CVE-2026-66324: Microsoft Edge path traversal spoofing vulnerability

CVE-2026-66324 · Severity: medium · CVSS 6.5 · Published 2026-08-28

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge, the company's web browser, contains a flaw that allows attackers to manipulate file paths and names, potentially leading to spoofing attacks where users are tricked into accessing malicious content. An attacker can exploit this over a network without authentication, compromising user trust in the browser's security indicators.

Technical details

The vulnerability is classified as external control of file name or path (CWE-434/CWE-22 class), affecting the Chromium-based Microsoft Edge browser. The flaw permits an attacker to influence file path or name handling, enabling spoofing attacks delivered over a network. Attack vector is network-based with no authentication required. An attacker can craft malicious requests to trick users into believing they are accessing legitimate content when in fact they are viewing attacker-controlled resources. Patches are available through Microsoft Security Updates.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-08-28: disclosed

References

Related threats