PatchSiren cyber security CVE debrief
CVE-2026-45495 Microsoft CVE debrief
A remote code execution vulnerability in Microsoft Edge (Chromium-based) allows an attacker to execute arbitrary code on affected systems. The vulnerability is rated HIGH severity with a CVSS 3.1 score of 8.8, indicating significant risk due to network attack vector, low attack complexity, and no required privileges—though user interaction is required. The affected product is Microsoft Edge Chromium prior to version 148.0.3967.70. The vulnerability was published in the NVD on May 18, 2026, with subsequent modification on May 19, 2026. Microsoft has issued a vendor advisory addressing this issue. Organizations should prioritize updating Edge Chromium to version 148.0.3967.70 or later.
- Vendor
- Microsoft
- Product
- Microsoft Edge (Chromium-based)
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-18
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-18
- Advisory updated
- 2026-05-26
Who should care
Organizations using Microsoft Edge (Chromium-based) in enterprise environments, security teams responsible for browser security posture, and end users relying on Edge for web browsing should prioritize this update.
Technical summary
CVE-2026-45495 is a remote code execution vulnerability in Microsoft Edge (Chromium-based). The vulnerability can be triggered with user interaction and allows an unauthenticated attacker to execute arbitrary code with the privileges of the browser process. The CVSS 3.1 score of 8.8 reflects network accessibility, low complexity, and high impact to confidentiality, integrity, and availability. Root cause weaknesses include improper input validation (CWE-20), code injection (CWE-94), and memory safety issues (CWE-119). The fix version 148.0.3967.70 addresses this vulnerability.
Defensive priority
HIGH
Recommended defensive actions
- Update Microsoft Edge (Chromium-based) to version 148.0.3967.70 or later
- Verify automatic update settings are enabled for Edge
- Review browser usage policies to ensure managed deployments receive security updates
- Monitor Microsoft Security Response Center advisories for related security updates
Evidence notes
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. CWE classifications include CWE-20 (Improper Input Validation), CWE-94 (Improper Control of Generation of Code), and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). Affected versions: Edge Chromium before 148.0.3967.70.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45495 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45495
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45495 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45495
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45495
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.