Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in Microsoft Edge (Chromium‑based) lets an attacker run arbitrary code in the context of the user who is running the browser. The vulnerability, identified as CWE‑416, arises when Edge incorrectly accesses data after it has been freed. If successfully triggered, an attacker can execute malicious code and potentially take control of the entire system hosting the browser. The flaw is exploitable by delivering specially crafted content over a network connection, enabling the attacker to manipulate the browser without user interaction.

Affected Systems

Microsoft Edge (Chromium‑based) on all current releases is affected. No specific version range is supplied, so every existing Edge installation may be vulnerable until a security update that addresses CVE‑2026‑57986 is installed.

Risk and Exploitability

The CVSS score of 7.5 denotes high severity, and an EPSS score of <1% indicates a very low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it can be triggered by unwitting users who load malicious or tampered web content, giving the attacker a network‑based attack vector to the browser.

Generated by OpenCVE AI on July 21, 2026 at 09:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the official Microsoft Edge security update that contains the fix for CVE‑2026‑57986.
  • Deploy the update across all endpoints using Windows Update, Microsoft Endpoint Manager, or another centralized patching solution to ensure that every user device receives the patch.
  • Until the patch is fully deployed, apply mitigations such as enabling Microsoft Defender SmartScreen, configuring Edge to block unknown or untrusted content, and limiting browsing to approved sites via group policy.

Generated by OpenCVE AI on July 21, 2026 at 09:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-23T23:56:08.312Z

Reserved: 2026-06-26T17:45:44.854Z

Link: CVE-2026-57986

cve-icon Vulnrichment

Updated: 2026-07-06T11:32:14.115Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:30:04Z

Weaknesses