Input validation error in Microsoft Edge - CVE-2026-58292

 

Input validation error in Microsoft Edge - CVE-2026-58292

Published: July 17, 2026


Vulnerability identifier: #VU138363
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58292
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content or opening a specially crafted file. A remote attacker can host a specially crafted website or provide a specially crafted file to execute arbitrary code.

User interaction is required, and successful exploitation requires the user to visit an attacker-controlled webpage or open crafted content. Successful exploitation also requires preparing the target environment to improve exploit reliability, and the impact may extend beyond the vulnerable component's security scope.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58292

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins