CVE Tools

Microsoft Edge

1,948 CVEs tracked. 44 of them are in CISA KEV.

This hub aggregates every CVE we track for Microsoft Edge, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.

Microsoft Edge CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Microsoft Edge CVEs per month
MonthCVEs
2024-1029
2024-1110
2024-125
2025-0117
2025-0213
2025-035
2025-0413
2025-057
2025-064
2025-078
2025-084
2025-0912
2025-102
2025-1134
2025-123
2026-012
2026-0213
2026-0345
2026-043
2026-05109
2026-0638
2026-071
2026-082
2026-090

Severity

How the 1,948 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical764%
  • High1,17860%
  • Medium65334%
  • Low412%

Latest CVEs

The 15 most recently published vulnerabilities affecting Microsoft Edge.

  1. CVE-2026-70331Microsoft Edge for iOS Spoofing Vulnerability5.4
  2. CVE-2026-66310Microsoft Edge for Android Information Disclosure Vulnerability7.7
  3. CVE-2026-62828Microsoft Edge for Android (Chromium-based) Tampering Vulnerability5.4
  4. CVE-2026-11236Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v...8.3
  5. CVE-2026-11237Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted H...8.3
  6. CVE-2026-11235Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox ...8.8
  7. CVE-2026-11233Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted...4.7
  8. CVE-2026-11232Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)5.4
  9. CVE-2026-11231Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)8.1
  10. CVE-2026-11230Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)8.8
  11. CVE-2026-11229Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security sev...6.1
  12. CVE-2026-11228Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a craf...4.3
  13. CVE-2026-11227Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)6.5
  14. CVE-2026-11224Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)8.1
  15. CVE-2026-11223Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a c...6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store