Junglewise Threat Intelligence

CVE-2026-66325: Microsoft Edge server-side request forgery

CVE-2026-66325 · Severity: medium · CVSS 6.1 · Published 2026-08-04

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions of users to access internet content. A server-side request forgery vulnerability allows an attacker to trick the browser into making unintended requests to internal resources or external services, potentially leading to unauthorized access to sensitive data or network resources, and enabling spoofing attacks that could compromise user trust and data security.

Technical details

A server-side request forgery (SSRF) vulnerability exists in Microsoft Edge (Chromium-based browser) that permits an unauthorized attacker to perform spoofing over a network. The vulnerability allows an attacker to manipulate the browser into making requests to unintended destinations, potentially to internal network services or external third-party systems. This is typically exploited through malicious web pages or application logic that doesn't properly validate or sanitize user-controlled URLs. An attacker can exploit this via the network to bypass access controls and interact with restricted resources. Patches or mitigations should be available through Microsoft's security update channels.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-08-04: disclosed

References

Related threats