Dettaglio notizia

Data 06/07/2026
Titolo Microsoft Edge Patches Multiple High-Severity RCE and Security Bypass Flaws
Contesto Microsoft Edge (Chromium-based) has received fixes for multiple high-severity vulnerabilities, including remote code execution flaws CVE-2026-58289, CVE-2026-58293, CVE-2026-58285, CVE-2026-58288, CVE-2026-57974, CVE-2026-58284, CVE-2026-58287, CVE-2026-57981, and CVE-2026-56645, as well as the security feature bypass issue CVE-2026-57983. Public records attribute the issues to Microsoft and rate them from high to critical severity, with CVSS scores reaching 9.0 for CVE-2026-58289 and several others scoring in the 8.1-8.8 range.

Advisories from Microsoft and HKCERT indicate the flaws affect Microsoft Edge and require prompt patching through the browser's latest security updates. While some metadata inconsistently marks the bugs as not remotely exploitable, the listed attack characteristics for several entries include low attack complexity, no privileges required, and in many cases user interaction, making browser update compliance and rapid deployment a priority for enterprise defenders.
Fonte https://mallory.ai/stories/019f2a76-66fe-762c-84ef-84f97feb5e08
Discussione? Parliamone sul Forum