Description:
Microsoft has released security updates to address multiple vulnerabilities in Microsoft Edge. A remote attacker could entice a user to open a web page with specially crafted content on a vulnerable browser to exploit the vulnerabilities.
Affected Systems:
- Microsoft Edge prior to version 148.0.3967.70
Impact:
Successful exploitation of the vulnerabilities could lead to remote code execution, denial of service, information disclosure, security restriction bypass or spoofing on an affected system.
Recommendation:
System administrators and users of affected systems should update Microsoft Edge to version 148.0.3967.70 or later to address the issue.
More Information:
- https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#may-15-2026
- https://www.hkcert.org/security-bulletin/microsoft-edge-multiple-vulnerabilities_20260518
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8509 (to CVE-2026-8519)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8523 (to CVE-2026-8563)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8565 (to CVE-2026-8573)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8575 (to CVE-2026-8582)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8584 (to CVE-2026-8587)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45492
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45494 (to CVE-2026-45495)