{"schema_version":1,"title":"Microsoft Edge vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 168 vulnerabilities in Microsoft Edge: 0 in the last 7 days and 77 in the last 90 days, 81 of them critical and 80 exploited in the wild. The most recent, CVE-2026-88097, was published on 18 September 2026.","url":"https://junglewise.ai/threats/technologies/edge-chromium-based","json_url":"https://junglewise.ai/threats/technologies/edge-chromium-based.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/edge-chromium-based","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":50,"all_time":168,"critical":81,"exploited":80,"last_7_days":0,"last_30_days":16,"last_90_days":77,"last_365_days":96},"latest":[{"cve":"CVE-2026-88097","cvss":8.1,"epss":0.0026,"slug":"cve-2026-88097-use-after-free-in-microsoft-edge-chromium-based-allows-an","title":"Microsoft Edge use after free privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-18T21:18:45.913+00:00","url":"https://junglewise.ai/threats/cve-2026-88097-use-after-free-in-microsoft-edge-chromium-based-allows-an"},{"cve":"CVE-2026-85893","cvss":8.8,"epss":0.0084,"slug":"cve-2026-85893-microsoft-edge-use-after-free-in-chromium","title":"Microsoft Edge use-after-free in Chromium","severity":"high","exploited":false,"published_at":"2026-09-15T23:19:12.11+00:00","url":"https://junglewise.ai/threats/cve-2026-85893-microsoft-edge-use-after-free-in-chromium"},{"cve":"CVE-2026-69486","cvss":8.8,"epss":0.0084,"slug":"cve-2026-69486-microsoft-edge-heap-based-buffer-overflow","title":"Microsoft Edge heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-15T23:17:41.633+00:00","url":"https://junglewise.ai/threats/cve-2026-69486-microsoft-edge-heap-based-buffer-overflow"},{"cve":"CVE-2026-85892","cvss":7.8,"epss":0.0021,"slug":"cve-2026-85892-microsoft-edge-race-condition-in-shared-resource-synchronization","title":"Microsoft Edge race condition in shared resource synchronization","severity":"high","exploited":false,"published_at":"2026-09-14T18:20:19.343+00:00","url":"https://junglewise.ai/threats/cve-2026-85892-microsoft-edge-race-condition-in-shared-resource-synchronization"},{"cve":"CVE-2026-77490","cvss":6.1,"epss":0.0042,"slug":"cve-2026-77490-microsoft-edge-cross-site-scripting-in-page-generation","title":"Microsoft Edge cross-site scripting in page generation","severity":"medium","exploited":false,"published_at":"2026-09-11T20:18:45.403+00:00","url":"https://junglewise.ai/threats/cve-2026-77490-microsoft-edge-cross-site-scripting-in-page-generation"},{"cve":"CVE-2026-70341","cvss":8.5,"epss":0.0066,"slug":"cve-2026-70341-microsoft-edge-use-after-free-vulnerability","title":"Microsoft Edge use-after-free vulnerability","severity":"high","exploited":false,"published_at":"2026-09-11T16:17:46.08+00:00","url":"https://junglewise.ai/threats/cve-2026-70341-microsoft-edge-use-after-free-vulnerability"},{"cve":"CVE-2026-87491","cvss":8.8,"epss":0.0314,"slug":"cve-2026-87491-google-chromium-v8-out-of-bounds-write-in-javascript-engine","title":"Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via","severity":"critical","exploited":true,"published_at":"2026-09-09T01:17:05.887+00:00","url":"https://junglewise.ai/threats/cve-2026-87491-google-chromium-v8-out-of-bounds-write-in-javascript-engine"},{"cve":"CVE-2026-85046","cvss":8.8,"epss":0.4888,"slug":"cve-2026-85046-google-chromium-v8-type-confusion-vulnerability","title":"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr","severity":"critical","exploited":true,"published_at":"2026-09-03T20:17:24.21+00:00","url":"https://junglewise.ai/threats/cve-2026-85046-google-chromium-v8-type-confusion-vulnerability"},{"cve":"CVE-2026-72984","cvss":8.8,"epss":0.0082,"slug":"cve-2026-72984-microsoft-edge-type-confusion-in-resource-access","title":"Microsoft Edge type confusion in resource access","severity":"high","exploited":false,"published_at":"2026-08-28T20:19:44.943+00:00","url":"https://junglewise.ai/threats/cve-2026-72984-microsoft-edge-type-confusion-in-resource-access"},{"cve":"CVE-2026-70331","cvss":5.4,"epss":0.0041,"slug":"cve-2026-70331-microsoft-edge-for-ios-prompt-injection-vulnerability","title":"Microsoft Edge for iOS prompt injection vulnerability","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:41.82+00:00","url":"https://junglewise.ai/threats/cve-2026-70331-microsoft-edge-for-ios-prompt-injection-vulnerability"},{"cve":"CVE-2026-70309","cvss":5.4,"epss":0.0021,"slug":"cve-2026-70309-microsoft-edge-origin-validation-error-security-feature-bypass","title":"Microsoft Edge origin validation error security feature bypass","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:40.267+00:00","url":"https://junglewise.ai/threats/cve-2026-70309-microsoft-edge-origin-validation-error-security-feature-bypass"},{"cve":"CVE-2026-66798","cvss":4.3,"epss":0.0079,"slug":"cve-2026-66798-microsoft-edge-use-after-free-in-chromium","title":"Microsoft Edge use-after-free in Chromium","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:34.673+00:00","url":"https://junglewise.ai/threats/cve-2026-66798-microsoft-edge-use-after-free-in-chromium"},{"cve":"CVE-2026-66324","cvss":6.5,"epss":0.0092,"slug":"cve-2026-66324-microsoft-edge-path-traversal-spoofing-vulnerability","title":"Microsoft Edge path traversal spoofing vulnerability","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:34.407+00:00","url":"https://junglewise.ai/threats/cve-2026-66324-microsoft-edge-path-traversal-spoofing-vulnerability"},{"cve":"CVE-2026-66323","cvss":5.4,"epss":0.0041,"slug":"cve-2026-66323-microsoft-edge-improper-neutralization-of-parameter-delimiters","title":"Microsoft Edge improper neutralization of parameter delimiters","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:34.28+00:00","url":"https://junglewise.ai/threats/cve-2026-66323-microsoft-edge-improper-neutralization-of-parameter-delimiters"},{"cve":"CVE-2026-62904","cvss":5.4,"epss":0.0039,"slug":"cve-2026-62904-microsoft-edge-incorrect-authorization-information-disclosure","title":"Microsoft Edge incorrect authorization information disclosure","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:25.13+00:00","url":"https://junglewise.ai/threats/cve-2026-62904-microsoft-edge-incorrect-authorization-information-disclosure"},{"cve":"CVE-2026-58616","cvss":4.4,"epss":0.003,"slug":"cve-2026-58616-microsoft-edge-copilot-chat-race-condition-information-disclosure","title":"Microsoft Edge Copilot Chat race condition information disclosure","severity":"medium","exploited":false,"published_at":"2026-08-28T20:18:44.927+00:00","url":"https://junglewise.ai/threats/cve-2026-58616-microsoft-edge-copilot-chat-race-condition-information-disclosure"},{"cve":"CVE-2026-72970","cvss":8.3,"epss":0.0073,"slug":"cve-2026-72970-microsoft-edge-heap-based-buffer-overflow","title":"Microsoft Edge heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-08-14T18:19:09.003+00:00","url":"https://junglewise.ai/threats/cve-2026-72970-microsoft-edge-heap-based-buffer-overflow"},{"cve":"CVE-2026-66326","cvss":6.5,"epss":0.0077,"slug":"cve-2026-66326-microsoft-edge-missing-authorization-allows-remote-code-execution","title":"Microsoft Edge missing authorization allows remote code execution","severity":"medium","exploited":false,"published_at":"2026-08-04T00:17:39.847+00:00","url":"https://junglewise.ai/threats/cve-2026-66326-microsoft-edge-missing-authorization-allows-remote-code-execution"},{"cve":"CVE-2026-66325","cvss":6.1,"epss":0.0039,"slug":"cve-2026-66325-microsoft-edge-server-side-request-forgery","title":"Microsoft Edge server-side request forgery","severity":"medium","exploited":false,"published_at":"2026-08-04T00:17:39.703+00:00","url":"https://junglewise.ai/threats/cve-2026-66325-microsoft-edge-server-side-request-forgery"},{"cve":"CVE-2026-66322","cvss":7.1,"epss":0.0023,"slug":"cve-2026-66322-microsoft-edge-origin-validation-error-enabling-spoofing-attacks","title":"Microsoft Edge origin validation error enabling spoofing attacks","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:39.577+00:00","url":"https://junglewise.ai/threats/cve-2026-66322-microsoft-edge-origin-validation-error-enabling-spoofing-attacks"},{"cve":"CVE-2026-66321","cvss":7.4,"epss":0.0107,"slug":"cve-2026-66321-microsoft-edge-type-confusion-vulnerability","title":"Microsoft Edge type confusion vulnerability","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:39.44+00:00","url":"https://junglewise.ai/threats/cve-2026-66321-microsoft-edge-type-confusion-vulnerability"},{"cve":"CVE-2026-66318","cvss":8.1,"epss":0.0036,"slug":"cve-2026-66318-microsoft-edge-origin-validation-error-allows-information","title":"Microsoft Edge origin validation error allows information disclosure","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:39.317+00:00","url":"https://junglewise.ai/threats/cve-2026-66318-microsoft-edge-origin-validation-error-allows-information"},{"cve":"CVE-2026-66317","cvss":5.4,"epss":0.0021,"slug":"cve-2026-66317-microsoft-edge-origin-validation-error-allows-network-tampering","title":"Microsoft Edge origin validation error allows network tampering","severity":"medium","exploited":false,"published_at":"2026-08-04T00:17:39.183+00:00","url":"https://junglewise.ai/threats/cve-2026-66317-microsoft-edge-origin-validation-error-allows-network-tampering"},{"cve":"CVE-2026-66316","cvss":5.4,"epss":0.0021,"slug":"cve-2026-66316-microsoft-edge-origin-validation-bypass-allowing-spoofing","title":"Microsoft Edge origin validation bypass allowing spoofing","severity":"medium","exploited":false,"published_at":"2026-08-04T00:17:39.06+00:00","url":"https://junglewise.ai/threats/cve-2026-66316-microsoft-edge-origin-validation-bypass-allowing-spoofing"},{"cve":"CVE-2026-66315","cvss":7.5,"epss":0.0061,"slug":"cve-2026-66315-microsoft-edge-use-after-free-vulnerability-in-chromium","title":"Microsoft Edge use-after-free vulnerability in Chromium","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:38.927+00:00","url":"https://junglewise.ai/threats/cve-2026-66315-microsoft-edge-use-after-free-vulnerability-in-chromium"}],"weekly":[{"week":"2026-06-29","critical":1,"exploited":0,"vulnerabilities":42},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":11},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-08-31","critical":1,"exploited":1,"vulnerabilities":1},{"week":"2026-09-07","critical":1,"exploited":1,"vulnerabilities":3},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Microsoft Windows","slug":"windows-","vulnerabilities":977,"url":"https://junglewise.ai/threats/technologies/windows-"},{"name":"Microsoft Windows 10","slug":"windows-10","vulnerabilities":588,"url":"https://junglewise.ai/threats/technologies/windows-10"},{"name":"Microsoft Windows 11","slug":"windows-11","vulnerabilities":493,"url":"https://junglewise.ai/threats/technologies/windows-11"},{"name":"Microsoft Windows Server 2012","slug":"windows-server-2012","vulnerabilities":293,"url":"https://junglewise.ai/threats/technologies/windows-server-2012"},{"name":"Microsoft Windows Server 2016","slug":"windows-server-2016","vulnerabilities":213,"url":"https://junglewise.ai/threats/technologies/windows-server-2016"},{"name":"Microsoft Windows Server 2019","slug":"windows-server-2019","vulnerabilities":211,"url":"https://junglewise.ai/threats/technologies/windows-server-2019"},{"name":"Microsoft Windows 11 24h2","slug":"windows-11-24h2","vulnerabilities":192,"url":"https://junglewise.ai/threats/technologies/windows-11-24h2"},{"name":"Microsoft Windows Server 2022","slug":"windows-server-2022","vulnerabilities":178,"url":"https://junglewise.ai/threats/technologies/windows-server-2022"},{"name":"Microsoft Windows 11 25h2","slug":"windows-11-25h2","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/windows-11-25h2"},{"name":"Microsoft Windows 11 Version 26H1","slug":"windows-11-version-26h1","vulnerabilities":135,"url":"https://junglewise.ai/threats/technologies/windows-11-version-26h1"},{"name":"Microsoft Windows Server 2025","slug":"windows-server-2025","vulnerabilities":124,"url":"https://junglewise.ai/threats/technologies/windows-server-2025"},{"name":"Microsoft Windows Server 2008","slug":"windows-server-2008","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/windows-server-2008"}],"technology":{"hub":true,"name":"Microsoft Edge","slug":"edge-chromium-based","vendor":{"name":"Microsoft","slug":"microsoft","url":"https://junglewise.ai/threats/vendors/microsoft"},"aliases":["edge"],"category":"web-browser","homepage":"https://www.microsoft.com/edge","description":"A web browser developed by Microsoft based on the Chromium open-source project.","url":"https://junglewise.ai/threats/technologies/edge-chromium-based"},"most_severe":[{"cve":"CVE-2014-1776","cvss":9.8,"slug":"cve-2014-1776-microsoft-internet-explorer-memory-corruption-vulnerability","title":"Microsoft Internet Explorer Memory Corruption Vulnerability","severity":"critical","exploited":true,"published_at":"2022-01-28T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2014-1776-microsoft-internet-explorer-memory-corruption-vulnerability"},{"cve":"CVE-2024-7971","cvss":9.6,"slug":"cve-2024-7971-google-chromium-v8-type-confusion-vulnerability","title":"Google Chromium V8 Type Confusion Vulnerability","severity":"critical","exploited":true,"published_at":"2024-08-26T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-7971-google-chromium-v8-type-confusion-vulnerability"},{"cve":"CVE-2024-5274","cvss":9.6,"slug":"cve-2024-5274-google-chromium-v8-type-confusion-vulnerability","title":"Google Chromium V8 Type Confusion Vulnerability","severity":"critical","exploited":true,"published_at":"2024-05-28T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-5274-google-chromium-v8-type-confusion-vulnerability"},{"cve":"CVE-2024-4671","cvss":9.6,"slug":"cve-2024-4671-google-chromium-visuals-use-after-free-vulnerability","title":"Google Chromium Visuals Use-After-Free Vulnerability","severity":"critical","exploited":true,"published_at":"2024-05-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-4671-google-chromium-visuals-use-after-free-vulnerability"},{"cve":"CVE-2022-3075","cvss":9.6,"slug":"cve-2022-3075-google-chromium-mojo-insufficient-data-validation-vulnerability","title":"Google Chromium Mojo Insufficient Data Validation Vulnerability","severity":"critical","exploited":true,"published_at":"2022-09-08T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3075-google-chromium-mojo-insufficient-data-validation-vulnerability"},{"cve":"CVE-2021-37973","cvss":9.6,"slug":"cve-2021-37973-google-chromium-portals-use-after-free-vulnerability","title":"Google Chromium Portals Use-After-Free Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-37973-google-chromium-portals-use-after-free-vulnerability"},{"cve":"CVE-2021-30633","cvss":9.6,"slug":"cve-2021-30633-google-chromium-indexed-db-api-use-after-free-vulnerability","title":"Google Chromium Indexed DB API Use-After-Free Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-30633-google-chromium-indexed-db-api-use-after-free-vulnerability"},{"cve":"CVE-2010-3962","cvss":9.3,"epss":0.8891,"slug":"cve-2010-3962-microsoft-internet-explorer-use-after-free-in-css-processing","title":"Microsoft Internet Explorer use-after-free in CSS processing","severity":"critical","exploited":true,"published_at":"2025-10-06T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2010-3962-microsoft-internet-explorer-use-after-free-in-css-processing"},{"cve":"CVE-2013-3893","cvss":8.8,"epss":0.8261,"slug":"cve-2013-3893-microsoft-internet-explorer-use-after-free-in-mshtml-dll","title":"Microsoft Internet Explorer use after free in mshtml.dll","severity":"critical","exploited":true,"published_at":"2025-08-12T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2013-3893-microsoft-internet-explorer-use-after-free-in-mshtml-dll"},{"cve":"CVE-2026-85046","cvss":8.8,"epss":0.4888,"slug":"cve-2026-85046-google-chromium-v8-type-confusion-vulnerability","title":"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr","severity":"critical","exploited":true,"published_at":"2026-09-03T20:17:24.21+00:00","url":"https://junglewise.ai/threats/cve-2026-85046-google-chromium-v8-type-confusion-vulnerability"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}