Description
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in Microsoft Edge (Chromium‑based) allows an attacker to send crafted data that causes the browser to execute arbitrary code. This flaw, categorized as CWE‑20, can lead to loss of confidentiality, integrity, and availability of the host system when exploited.

Affected Systems

Microsoft Edge (Chromium‑based) is affected. No specific version numbers are disclosed; all current releases should be treated as potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests exploitation is unlikely in the short term. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been reported. Based on the description, the likely attack vector is a remote network injection that delivers malicious input to the browser process, allowing code execution with the privileges of the running instance.

Generated by OpenCVE AI on July 21, 2026 at 09:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version that contains the fix for CVE‑2026‑58292.
  • Restrict external data that can be processed by the browser, for example by configuring firewall rules to block unsolicited inbound traffic to the browser process.
  • Configure Edge to use sandboxing and only allow trusted sites or content, reducing the impact of potential input validation failures.

Generated by OpenCVE AI on July 21, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-20
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T00:00:41.014Z

Reserved: 2026-06-29T21:59:30.871Z

Link: CVE-2026-58292

cve-icon Vulnrichment

Updated: 2026-07-06T11:49:30.983Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:15:02Z

Weaknesses
  • CWE-20

    Improper Input Validation