CVE-2026-58288 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-58288 Microsoft US
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-58288 Microsoft US
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-58286 Microsoft US
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-58285 Microsoft US
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-58284 Microsoft US
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-58278 Microsoft US
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-58276 Microsoft US
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-57986 Microsoft US
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-57981 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-57977 Microsoft US
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-57974 Microsoft US
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-45488 Microsoft US
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-58522 Microsoft US
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-58299 Microsoft US
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-58287 Microsoft US
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-58283 Microsoft US
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-58282 Microsoft US
Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-56646 Microsoft US
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-57993 Microsoft US
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-57992 Microsoft US
Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-57988 Microsoft US
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-57987 Microsoft US
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-57985 Microsoft US
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-57984 Microsoft US
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
EPSS 0.01 CVE-2026-57983 Microsoft US
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-57975 Microsoft US
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-56645 Microsoft US
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-55945 Microsoft US
Information published.
EPSS 0.01 CVE-2026-45489 Microsoft US
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-54998 Microsoft US
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-41106 Microsoft US
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-26145 Microsoft US
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-57100 Microsoft US
Break-glass credential revocation is live on GitHub Enterprise. The Trivy and Microsoft durabletask repeats show why fast, complete revocation was needed.. Category: News
Huntress is seeing an ongoing password spray attack against Microsoft Azure CLI that originates from an IPv6 address range controlled by LSHIY LLC.
Microsoft US
Most Microsoft 365 environments are missing more than half of the recommended security controls, even with tooling in place. Here's why that happens and what Huntress Managed ISPM does about it.
Microsoft US
Cybercriminals are hijacking Microsoft 365 accounts in seconds. Learn the 2026 hacker tactics, including ConsentFix, that bypass security training and exploit normal user behavior.
Microsoft US
Added Edge software to the Security Updates table. Customers that are running supported version of Edge are encouraged to update to the indicated version to be protected from this vulnerability.
EPSS 0.00 CVE-2026-50521 Microsoft US
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Oracle PeopleSoft. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2026-35273.
KEV ✓ · ransomware EPSS 0.95 CVSS 9.8 CVE-2026-35273 Oracle Google Microsoft školství US
A previously undocumented Windows loader tracked as OXLOADER is delivering the CASTLESTEALER infostealer via malicious Google Ads, with low detection rates across static engines and sandbox detonations. The loader uses several obfuscation layers (control-flow flattening, opaque predicates, mixed Boolean-Arithmetic), self-modifying decryption stubs, and abuses the Windows .reloc section to stage shellcode. Elastic Security Labs identified OXLOADER in an active campaign targeting one of our…
AAD Graph Activity Logs are now ingestible into Elastic and usable for threat detection within the SIEM/XDR solution. That sentence shouldn't be exciting, but it is. For most of the past decade, this slice of telemetry simply didn't exist as a customer-accessible log stream. Microsoft Graph Activity Logs (the modern graph.microsoft.com surface) went GA in April 2024. The legacy graph.windows.net surface, the one adversary tooling actually hits, stayed dark until early 2026. This post walks the…
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-47645 Microsoft US
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-48582 Microsoft US
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-48584 Microsoft US
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-47647 Microsoft US
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
EPSS 0.01 CVE-2026-42895 Microsoft US
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-47633 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-32208 Microsoft US
Huntress Managed ISPM finds and closes Microsoft 365 identity gaps before attackers do. Learn why visibility isn't enough and what real identity hardening takes.
Microsoft US
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
EPSS 0.11 CVE-2026-50656 Microsoft US
A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages
Microsoft SK
A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Microsoft és az Adobe szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán azok súlyossága, a szoftverek széleskörű elterjedtsége, valamint az egyes biztonsági hibákat érintő aktív kihasználások miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 206 különböző biztonsági hibát javított, köztük 3 db nulladik napi (zero-day) sebezhetőséget is, […]
Huntress traced device code phishing from Tencent Cloud to Kali365, a Microsoft 365 kit that steals tokens and keeps access even after MFA or password resets.
209 patches + 388 advisories = welcome to summer 2026Categories: Threat ResearchTags: x-ops, Patch Tuesday, MICROSOFT PATCH TUESDAY
Microsoft GB
On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors. It is strongly recommended updating affected Windows servers as soon as possible.
Microsoft JP
I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for June 2026For June,…
KEV ✓ EPSS 0.54 CVSS 10.0 CVE-2025-10263 CVE-2026-32193 CVE-2026-41091 CVE-2026-44815 CVE-2026-45585 CVE-2026-45586 CVE-2026-45657 CVE-2026-47291 CVE-2026-47644 CVE-2026-48567 CVE-2026-49160 CVE-2026-50507 Adobe Microsoft US
Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-44810 Microsoft US
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
EPSS 0.02 CVE-2026-42986 Microsoft US
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50512 Microsoft US
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50511 Microsoft US