Description:
Microsoft has released security updates to address multiple vulnerabilities in Microsoft Edge. A remote attacker could entice a user to open a web page with specially crafted content on a vulnerable browser to exploit the vulnerabilities.
Reports indicated that a remote code execution vulnerability (CVE-2026-87491) is being exploited in the wild. System administrators are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
Affected Systems:
- Microsoft Edge prior to version 153.0.4234.32
Impact:
Successful exploitation of the vulnerabilities could lead to remote code execution, denial of service, elevation of privilege, information disclosure, security restriction bypass, spoofing or tampering on an affected system.
Recommendation:
System administrators and users of affected systems should update Microsoft Edge to version 153.0.4234.32 or later to address the issue.
More Information:
- https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#september-10-2026
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-76017 (to CVE-2026-76019)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-76021 (to CVE-2026-76023)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-76036
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-76039
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77490
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84330
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84333
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-84352
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-85042 (to CVE-2026-85043)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-85045
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-85048 (to CVE-2026-85049)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-85051 (to CVE-2026-85053)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-87491