Description:
Microsoft has released security updates to address multiple vulnerabilities in Microsoft Edge. A remote attacker could entice a user to open a web page with specially crafted content on a vulnerable browser to exploit the vulnerabilities.
Affected Systems:
- Microsoft Edge prior to version 149.0.4022.98
Impact:
Successful exploitation of the vulnerabilities could lead to remote code execution, denial of service, elevation of privilege, information disclosure or security restriction bypass on an affected system.
Recommendation:
System administrators and users of affected systems should update Microsoft Edge to version 149.0.4022.98 or later to address the issue.
More Information:
- https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#june-26-2026
- https://www.hkcert.org/security-bulletin/microsoft-edge-remote-code-execution-vulnerability_20260629
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-11647
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12028
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12030
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12032
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12438
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12442
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12448
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12469
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13021 (to CVE-2026-13027)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13029
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13031
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13033 (to CVE-2026-13036)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13038
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50521