CVE-2026-58289Disclosure(microsoft / edge_chromium)

MEDIUMCVSS 8.3 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch microsoft edge_chromium systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • edge_chromium

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 4 mentions (2026-07-04); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
edge_chromium

Deep dive

Activity timeline9 mentions / 6d
01234Mentions · 2026-07-03: 1Mentions · 2026-07-04: 4Mentions · 2026-07-05: 1Mentions · 2026-07-07: 1Mentions · 2026-07-24: 1Mentions · 2026-07-29: 1Active Exploitation · 2026-07-05: 1Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-05: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-04: 3Technical Details · 2026-07-05: 1Technical Details · 2026-07-24: 1Technical Details · 2026-07-29: 107-0307-0407-0507-0707-2407-29
Signal classification4 categories
Disclosure
555.6%
Patch
222.2%
Active Exploitation
111.1%
General
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-07-031
Patch1
2026-07-044
Disclosure3Patch1
2026-07-051
Active Exploitation1
2026-07-071
Disclosure1
2026-07-241
Disclosure1
2026-07-291
General1
Full discourse9 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Microsoft Edge (Chromium) Type Confusion RCE (CVE-2026-58289) A type confusion flaw (CWE-843) in Microsoft Edge (Chromium-based) lets an attacker access a resource using an incompatible type and execute code over a network. Malicious web content can trigger confusion and run arbitrary code in the browser context. Rated CVSS 9.0 with a scope change and high confidentiality, integrity, and availability impact - the classic browser drive-by RCE pattern in the Chromium engine. Attack complexity is high, but no privileges are required. 👉Update Microsoft Edge to 150.0.4078.48 or later.

    Post summary

    The post announces a critical type‑confusion RCE in Microsoft Edge, describes its technical characteristics, and advises users to update to version 150.0.4078.48 or newer.

    00001109
    236 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2026-58289: Microsoft Edge Type Confusion — Remote Code Execution Defense "The National Vulnerability Database (NVD) has published CVE-2026-58289, a Critical severity…" 🔗 https://securityarsenal.com/blog/cve-2026-58289-microsoft-edge-type-confusion-remote-code-execution-defense #CyberSecurity #ThreatIntel #cve202658289 #critical #cve

    Post summary

    The post announces the publication of CVE-2026-58289 as a critical severity issue but does not provide any PoC, exploit details, or mitigation information.

    0001066
    18 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-58289 — CVSS 9/10 █████████░ Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/vL1N3YWhin

    Post summary

    The post announces CVE‑2026‑58289, a critical type‑confusion vulnerability in Microsoft Edge, and confirms that a patch is available while providing no exploit details.

    10000376
    64 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-58289: Microsoft Edge Type Confusion Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04rbdN50

    Post summary

    The post references Microsoft Edge’s type‑confusion flaw but offers no PoC, exploit, or patch details beyond the headline.

    0000031
    32 followersView on X
  • NCA Azerbaijan@NCAAzerbaijan
    Disclosure

    "Microsoft Edge" brauzerində uzaqdan kod icrası riski (CVE-2026-58289) aşkarlanıb. #MKA #NCA #MilliCERT #Cybersecurity #Kibertəhlükəsizlik #Xəbərdarlıq https://t.co/xiul8ICEEk

    Post summary

    An announcement reports that CVE‑2026‑58289, a remote code execution vulnerability, has been discovered in Microsoft Edge, with no exploitation, PoC, or patch details provided.

    00000318
    135 followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-58289](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289) Access of ... https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289 #Vulnerability #CVE #ZeroDay

    Post summary

    The post merely announces a new CVE and links to Microsoft's update guide, providing no further technical or exploitation details.

    0000049
    9 followersView on X
  • ThreatAft@ThreatAft
    Active Exploitation

    🚨 CRITICAL: Microsoft Edge July 2026 Security Update CVE-2026-58289 — CVSS 9.0 CRITICAL — ACTIVE EXPLOITATION CONFIRMED 7 CVEs patched total. Update to Edge 150.0.4078.48 NOW. 🔗 https://threataft.com/articles/microsoft-edge-july-2026-security-update-cves?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel #infosec #MicrosoftEdge

    Post summary

    The post asserts that CVE‑2026‑58289 is being actively exploited and urges an immediate Edge update to mitigate the critical vulnerability.

    0000070
    32 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58289 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-58289 ----- Traducción: CVE-2026-58289 Acceso a un… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑58289, providing a brief technical description and a link to the official CVE record, with no evidence of active exploitation, patches, or false positive claims.

    0000039
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-58289 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-58289

    Post summary

    The text discloses CVE-2026-58289, detailing a type confusion vulnerability in Microsoft Edge that permits remote code execution.

    00000724
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftedge_chromium---

Explore more