Description:
Microsoft has released security updates to address multiple vulnerabilities in Microsoft Edge. A remote attacker could entice a user to open a web page with specially crafted content on a vulnerable browser to exploit the vulnerabilities.
Affected Systems:
- Microsoft Edge prior to version 148.0.3967.55
Impact:
Successful exploitation of the vulnerabilities could lead to remote code execution, elevation of privilege, information disclosure, security restriction bypass, spoofing or tampering on an affected system.
Recommendation:
System administrators and users of affected systems should update Microsoft Edge to version 148.0.3967.55 or later to address the issue.
More Information:
- https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#may-11-2026
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7897
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7905
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7912 (to CVE-2026-7913)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7915
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7931
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7941
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7993
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8020
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40416
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41107
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42838