Skip to content
ThreatCluster

Multiple Chromium CVEs Addressed in Microsoft Edge Security Update

First seen 15 Sep 2026, 21:04 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 21:59 UTC
  • Six Chromium CVEs were disclosed, affecting Microsoft Edge.
  • Vulnerabilities include incorrect authorization and race conditions.
  • Users are urged to update their browsers to the latest version.

On September 15, 2026, Microsoft announced the resolution of several vulnerabilities in Chromium, affecting the Microsoft Edge browser. The vulnerabilities include CVE-2026-87466, CVE-2026-87509, CVE-2026-87614, CVE-2026-87505, CVE-2026-87615, and CVE-2026-87613, all related to incorrect authorization and race conditions in various components. These vulnerabilities were published on September 9, 2026, and are linked to potential exploitation risks in the Edge browser. Users are advised to update their browsers to the latest version to mitigate these vulnerabilities. The vulnerabilities primarily affect users of Microsoft Edge (Chromium-based) as it utilizes Chromium OSS. Microsoft has documented these vulnerabilities in their Security Update Guide to inform users that the latest version is no longer vulnerable. No active exploitation has been reported as of the latest updates.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-09
Multiple CVEs published
CVE-2026-87466, CVE-2026-87509, CVE-2026-87614, CVE-2026-87505, CVE-2026-87615, and CVE-2026-87613 were published, detailing vulnerabilities in Chromium.
Api.Msrc.Microsoft
2026-09-09
CVE-2026-87505 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-09
CVE-2026-87615 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-09
CVE-2026-87509 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-09
CVE-2026-87613 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-09
CVE-2026-87466 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-09
CVE-2026-87614 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-15
Security update announced
Microsoft announced that the latest version of Microsoft Edge is no longer vulnerable to the disclosed CVEs.
Api.Msrc.Microsoft

More articles in this cluster (12)

Following this threat?

Track CVE-2026-87466 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed