Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, denial of service condition, security restriction bypass, spoofing and sensitive information disclosure on the targeted system.
CVE-2026-3910 is being exploited in the wild. A remote attacker could use this flaw to execute arbitrary code inside a sandbox via a crafted HTML page.
Hence, the risk level is rated as Extremely High Risk.
Before installation of the software, please visit the software vendor web-site for more details.
Apply fixes issued by the vendor:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
