Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, denial of service condition, security restriction bypass, data manipulation, sensitive information disclosure and spoofing on the targeted system.
CVE-2026-5281 is being exploited in the wild. The vulnerability allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. Hence, the risk level is rated as High Risk.
Before installation of the software, please visit the software vendor web-site for more details.
Apply fixes issued by the vendor:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
