Description
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in Microsoft Edge (Chromium‑based) allows an unauthorized attacker to execute code over a network. The flaw is classified as CWE‑20 and can cause the browser to treat malicious content as legitimate executable code, resulting in a loss of confidentiality, integrity, and availability of the affected machine.

Affected Systems

Microsoft Edge (Chromium‑based) is the only product mentioned. No specific version information is included, so all current releases of this browser are potentially affected until Microsoft releases a patch.

Risk and Exploitability

The CVSS score of 7.6 indicates high severity, while the EPSS score of less than 1 % suggests that exploitation is expected to be rare at present. The vulnerability is not included in the CISA KEV catalog. Attackers can exploit the flaw by delivering malicious content to an unpatched instance of the browser over the network.

Generated by OpenCVE AI on July 21, 2026 at 09:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge update that contains the fix for CVE‑2026‑57985.
  • If the patch cannot be applied immediately, use network filtering or a web application firewall to block traffic that could carry malicious content to the browser.
  • As a temporary containment measure, consider disabling or restricting external content loading in Edge or switching to a restricted browsing mode until the update is available.

Generated by OpenCVE AI on July 21, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-20
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-23T23:56:07.734Z

Reserved: 2026-06-26T17:45:44.854Z

Link: CVE-2026-57985

cve-icon Vulnrichment

Updated: 2026-07-06T11:42:20.011Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:30:04Z

Weaknesses
  • CWE-20

    Improper Input Validation