Description
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE‑2026‑57987 is a server‑side request forgery flaw (CWE‑918) located in Microsoft Edge (Chromium‑based). The browser can be coerced into issuing HTTP/HTTPS requests to arbitrary network destinations, allowing a malicious actor to spoof internal services or exfiltrate data from the victim’s machine. The vulnerability does not grant remote code execution or direct system control, but it effectively bypasses the browser’s protection against outbound network visibility.

Affected Systems

Microsoft Edge (Chromium‑based) is the affected product. No specific build or version range is disclosed in the advisory, so any build of Edge that contains the Chromium‑based code may be vulnerable until a security update is applied. Administrators should install updates as soon as they become available.

Risk and Exploitability

The CVSS base score of 6.5 indicates medium severity. An EPSS score of < 1% points to a very low probability of exploitation, and the issue is not listed in CISA’s KEV catalog, suggesting no widely known active exploits. The likely attack vector is remote content that triggers SSRF – typically via phishing, compromised webpages, or malicious add‑ons – which would cause the victim’s browser to forward requests to internal or attacker‑controlled endpoints.

Generated by OpenCVE AI on July 21, 2026 at 09:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge security update that addresses CVE‑2026‑57987.
  • Configure group‑policy or Edge settings to restrict outbound requests to sensitive internal network ranges.
  • Deploy network perimeter controls such as web proxies or WAFs to detect and block anomalous outbound traffic from browsers.

Generated by OpenCVE AI on July 21, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-22T20:30:04.113Z

Reserved: 2026-06-26T17:45:44.854Z

Link: CVE-2026-57987

cve-icon Vulnrichment

Updated: 2026-07-06T16:29:56.320Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:30:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)