logo

CVE-2026-57990: Microsoft Edge Exposes Local Files and Directories to Remote Attackers

ID: fdc5cb30-cfac-5e3a-b9ac-d9abd04b2fdc

STIX ID: report--fdc5cb30-cfac-5e3a-b9ac-d9abd04b2fdc

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-07-26

Date Updated: 2026-07-27

...
...

Microsoft disclosed CVE-2026-57990, a high-severity (CVSS 7.4) access-control flaw in Chromium-based Edge that can allow unauthenticated, remote attackers to read local files, browser profile data, or internal network content via a crafted web page; Microsoft released a patch (Edge 150.0.4078.99 or later) and recommends immediate updates and enterprise deployment controls, with no known in-the-wild exploitation as of 2026-07-26.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.