CVE-2026-57990: Microsoft Edge Exposes Local Files and Directories to Remote Attackers
ID: fdc5cb30-cfac-5e3a-b9ac-d9abd04b2fdc
STIX ID: report--fdc5cb30-cfac-5e3a-b9ac-d9abd04b2fdc
Feed Name: CosmicBytez Labs
Threat Score
Microsoft disclosed CVE-2026-57990, a high-severity (CVSS 7.4) access-control flaw in Chromium-based Edge that can allow unauthenticated, remote attackers to read local files, browser profile data, or internal network content via a crafted web page; Microsoft released a patch (Edge 150.0.4078.99 or later) and recommends immediate updates and enterprise deployment controls, with no known in-the-wild exploitation as of 2026-07-26.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
