CVE-2026-50521Disclosure(microsoft / edge_chromium)

LOWCVSS 8.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft edge_chromium systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • edge_chromium

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 5 mentions (2026-07-02); latest day: 1
  • 12 total mentions across 5 days

Affected systems

Vendors
Products
edge_chromium

Deep dive

Activity timeline12 mentions / 5d
01345Mentions · 2026-06-27: 1Mentions · 2026-07-01: 2Mentions · 2026-07-02: 5Mentions · 2026-07-21: 3Mentions · 2026-07-26: 1PoC Mentioned / Linked · 2026-07-02: 1Patch / Workaround · 2026-06-27: 1Patch / Workaround · 2026-07-02: 2Patch / Workaround · 2026-07-21: 1Technical Details · 2026-07-01: 2Technical Details · 2026-07-02: 3Technical Details · 2026-07-21: 3Technical Details · 2026-07-26: 106-2707-0107-0207-2107-26
Signal classification4 categories
Disclosure
650.0%
Patch
325.0%
General
216.7%
PoC
18.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-271
Patch1
2026-07-012
Disclosure2
2026-07-025
Disclosure2Patch2PoC1
2026-07-213
Disclosure2General1
2026-07-261
General1
Full discourse12 posts
  • YogSotho@YogSoth0
    Patch

    #CVE-2026-50521 Exploit Kit #Microsoft #Edge (#Chromium-based) Use-After-Free Remote Code Execution **CVE ID**: CVE-2026-50521 **CVSS Score**: 8.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) **Exploit Maturity**: Unproven (No public exploit available) **Patch Status**: Official Fix Available (Edge ≥ 149.0.4022.98) Attack Vector - **Network**: Remotely exploitable across the internet - **Complexity**: Low - Exploitation is straightforward - **Authentication**: Low privileges required - **User Interaction**: None required (zero-click) YES, IT'S A FUCKING MICROSOFT EDGE EXPLOIT 🫪 #0days #exploit #cybersecurity #security #hacking #RCE #antisec #infosec

    Post summary

    CVE‑2026‑50521 is a use‑after‑free RCE in Microsoft Edge with a CVSS of 8.3, no public exploit yet, but an official patch is available.

    014148207.6K
    1.9K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    صدرت ثغرة في البرنامج الموجود تقريبا على اغلب اجهزه الشركات والجهات والبطل كالعادة، Microsoft Edge اللي محد يفتحه لكنه موجود بكل جهاز تقريباً. رقم الثغرة CVE-2026-50521 بتقييم 8.3 الثغرة تسمح بتنفيذ أوامر عن بعد (Remote Code Execution) حسب Microsoft: الاستغلال غير معلن للعامة وغير مستغل حالياً. رغم ان استغلال الثغرة يحتاج مجموعه شروط وصلاحيات لكن مهم الحرص على التحديث لآخر اصدار

    Post summary

    CVE‑2026‑50521 is a high‑severity RCE vulnerability in Microsoft Edge, not yet exploited; users are advised to update to the latest version to mitigate the risk.

    33014114.3K
    50.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-50521 Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-50521

    Post summary

    The text announces CVE‑2026‑50521, highlighting a use‑after‑free flaw in Microsoft Edge that could enable code execution over a network.

    01021737
    58.0K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE ID: CVE-2026-50521 CVSS Score: 8.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) Exploit Maturity: Unproven (No public exploit available) Patch Status:

    Post summary

    The post simply discloses CVE‑2026‑50521 details, including its CVSS score and exploit status, but provides no evidence of an exploit, patch, or active use.

    1000046
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Source: X search for RCE 2026 exploit Posted: 2026-07-02T03:52:34.000Z Likes: 47 #CVE-2026-50521 Exploit Kit #Microsoft #Edge (#Chromium-based) Use-After-Free Remote Code Execution CVE ID: CVE-2026-50521 CVSS Score: 8.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L)…

    Post summary

    The tweet announces CVE‑2026‑50521 as a high‑severity Use‑After‑Free RCE in Microsoft Edge, but provides only basic technical details without any PoC, exploit code, or patch information.

    1000075
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-50521: #CVE-2026-50521 Exploit Kit #Microsoft #Edge (#Chromium-based) Use-After-Free Remote Code Execution CVE ID: CVE-2026-50521 CVSS Score: 8.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) Exploit Maturity: Unproven (No public exploit available) Patch Status:…

    Post summary

    CVE-2026-50521 is a Use‑After‑Free Remote Code Execution vulnerability in Microsoft Edge with a CVSS 8.3 score, no public exploit available, and its patch status is mentioned.

    1000089
    326 followersView on X
  • YogSotho@YogSoth0
    PoC

    @vysecurity Hope this helps 🫶🏻 It's just a weaponized PoC of CVE-2026-50521 https://t.co/bs6O1K3N1z

    Post summary

    A weaponized Proof of Concept for CVE-2026-50521 is provided via a link, but no exploit details, patch, or active attack evidence are mentioned.

    10000183
    1.6K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-50521 - Critical Use After Free in #Microsoft Edge. Remote code execution over network. #CVSS 8.3. No patch yet. Mitigate now. #CVEAlert #Microsoft #infosec #devsecops #devops #sysadmin #readteam #blueteam More detailed info: https://www.valtersit.com/cve/CVE-2026-50521

    Post summary

    The tweet reports CVE‑2026‑50521—a critical use‑after‑free in Microsoft Edge that allows remote code execution, with an 8.3 CVSS score and no patch yet, urging users to mitigate.

    0001064
    968 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-50521: Microsoft Edge Use-After-Free Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04qMQXy0

    Post summary

    The text announces Microsoft Edge Use‑After‑Free vulnerability CVE‑2026‑50521 and hints at business response measures, but lacks detailed technical, exploit, or patch information.

    0000038
    32 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Microsoft Edge (CVE-2026-50521) https://vuldb.com/vuln/375687

    Post summary

    The message announces a newly disclosed CVE-2026-50521 for Microsoft Edge with elevated severity, but offers no further technical, exploit, or mitigation details.

    00000124
    2.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-50521 Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-50521 ----- Traducción: CVE-2026-50521 Uso después de liberar en Microsoft Edge (basado en Chromium… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-50521, a use‑after‑free vulnerability in Microsoft Edge that could lead to remote code execution, but no PoC, exploit, or patch details are provided.

    0000038
    90 followersView on X
  • kawn@kawn2020
    Patch

    #microsoftupdate #securityupdate #Edge マイクロソフトが Microsoft Edge for Stable (Version 149.0.4022.98) をリリース. CVE ベースで脆弱性 1 件に対処. ・CVE-2026-50521 https://x.com/kawn2020/status/2070688150956159352

    Post summary

    Microsoft released Edge Stable 149.0.4022.98 with a patch for CVE‑2026‑50521.

    0000093
    91 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftedge_chromium---

Explore more