CVE-2026-57992Disclosure(microsoft / edge_chromium)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft edge_chromium systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • edge_chromium

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-07-05); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
edge_chromium

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-07-05: 1Mentions · 2026-07-06: 1Mentions · 2026-07-07: 1Mentions · 2026-07-13: 1Mentions · 2026-08-02: 1Active Exploitation · 2026-07-07: 1Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-13: 1Technical Details · 2026-08-02: 107-0507-0607-0707-1308-02
Signal classification4 categories
Disclosure
240.0%
Patch
120.0%
Active Exploitation
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-051
Disclosure1
2026-07-061
Patch1
2026-07-071
Active Exploitation1
2026-07-131
Disclosure1
2026-08-021
General1
Full discourse5 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-57992 - Use After Free in #Microsoft #Edge (Chromium-based) allows network-based code execution. #CVSS 7.5. No patch available yet. Monitor for updates & apply immediately. #CVEAlert #Microsoft #infosec #sysadmin #devops More FREE info: https://www.valtersit.com/cve/CVE-2026-57992/

    Post summary

    The tweet alerts that a Use After Free flaw (CVE‑2026‑57992) in Microsoft Edge can lead to network‑based code execution, scores 7.5, and no patch is yet available.

    10020245
    1.0K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Microsoft Edge の脆弱性 CVE-2026-57992:Chromium エンジンに起因する RCE https://iototsecnews.jp/2026/07/06/microsoft-edge-vulnerability-allows-remote-attacker-to-execute-arbitrary-code/ Microsoft Edge (Chromium ベース) の自動入力機能において、データの参照タイミングに不整合が生じるメモリ管理の不具合が確認されました。この脆弱性 CVE-2026-57992 は、閲覧中の画面で特定の操作が重なった際に、すでに解放されたメモリ領域をブラウザが誤って読み込んでしまう Use-After-Free の欠陥に起因します。この隙を突かれると、細工された不審なサイトを閲覧した際に、最悪のシナリオとしてリモートからプログラムを不正に実行され、システム制御を奪取されるなどの深刻な影響を受ける恐れがあります。現時点では公式パッチの準備中であるため、安全のための対応策として、セキュリティ情報の更新を注視しながら、組織内での自動入力機能の一時的な制限や、不審なリンクへのアクセスを控える、防衛統制を徹底することが大切です。 #CVE202657992 #Edge #Microsoft #Vulnerability

    Post summary

    The article announces a new CVE-2026-57992 affecting Microsoft Edge, details a Use‑After‑Free vulnerability that could lead to remote code execution, and notes that a vendor patch is under preparation with interim mitigation steps advised.

    00001194
    500 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-57992: Microsoft Edge Remote Code Execution Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04rBgmX0

    Post summary

    The article announces a Microsoft Edge RCE vulnerability (CVE-2026-57992) but offers no specific technical details, exploit code, patch information, or evidence of active exploitation.

    0000061
    32 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Active Exploitation

    🚨 #Microsoft Edge 0-Day Under Active Attack – #CVE-2026-57992 Use-After-Free Flaw Exposes Millions to Remote Code Execution + Video https://undercodetesting.com/microsoft-edge-0-day-under-active-attack-cve-2026-57992-use-after-free-flaw-exposes-millions-to-remote-code-execution-video/ Educational Purposes!

    Post summary

    Microsoft Edge’s CVE‑2026‑57992 is a use‑after‑free flaw reported to be actively exploited for remote code execution, yet the text offers no PoC, exploit tool details, or patch information.

    0000075
    646 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    A critical vulnerability in Microsoft Edge (CVE-2026-57992) could allow remote code execution via a use-after-free flaw. Users should update their browsers immediately to mitigate this high-severity risk. #MicrosoftEdge #CVE202657992 #CyberSecurity #BrowserSecurity #RemoteCodeExecution #SecurityUpdate https://thedailytechfeed.com/critical-microsoft-edge-vulnerability-enables-remote-code-execution/

    Post summary

    The tweet highlights a critical remote‑code‑execution flaw in Microsoft Edge, urging users to apply the advisory update immediately to mitigate the high‑severity risk.

    0000081
    486 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftedge_chromium---

Explore more