Impact
CVE‑2026‑57987 is a server‑side request forgery flaw (CWE‑918) located in Microsoft Edge (Chromium‑based). The browser can be coerced into issuing HTTP/HTTPS requests to arbitrary network destinations, allowing a malicious actor to spoof internal services or exfiltrate data from the victim’s machine. The vulnerability does not grant remote code execution or direct system control, but it effectively bypasses the browser’s protection against outbound network visibility.
Affected Systems
Microsoft Edge (Chromium‑based) is the affected product. No specific build or version range is disclosed in the advisory, so any build of Edge that contains the Chromium‑based code may be vulnerable until a security update is applied. Administrators should install updates as soon as they become available.
Risk and Exploitability
The CVSS base score of 6.5 indicates medium severity. An EPSS score of < 1% points to a very low probability of exploitation, and the issue is not listed in CISA’s KEV catalog, suggesting no widely known active exploits. The likely attack vector is remote content that triggers SSRF – typically via phishing, compromised webpages, or malicious add‑ons – which would cause the victim’s browser to forward requests to internal or attacker‑controlled endpoints.
OpenCVE Enrichment