PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45495 Microsoft CVE debrief

A remote code execution vulnerability in Microsoft Edge (Chromium-based) allows an attacker to execute arbitrary code on affected systems. The vulnerability is rated HIGH severity with a CVSS 3.1 score of 8.8, indicating significant risk due to network attack vector, low attack complexity, and no required privileges—though user interaction is required. The affected product is Microsoft Edge Chromium prior to version 148.0.3967.70. The vulnerability was published in the NVD on May 18, 2026, with subsequent modification on May 19, 2026. Microsoft has issued a vendor advisory addressing this issue. Organizations should prioritize updating Edge Chromium to version 148.0.3967.70 or later.

Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-18
Original CVE updated
2026-05-26
Advisory published
2026-05-18
Advisory updated
2026-05-26

Who should care

Organizations using Microsoft Edge (Chromium-based) in enterprise environments, security teams responsible for browser security posture, and end users relying on Edge for web browsing should prioritize this update.

Technical summary

CVE-2026-45495 is a remote code execution vulnerability in Microsoft Edge (Chromium-based). The vulnerability can be triggered with user interaction and allows an unauthenticated attacker to execute arbitrary code with the privileges of the browser process. The CVSS 3.1 score of 8.8 reflects network accessibility, low complexity, and high impact to confidentiality, integrity, and availability. Root cause weaknesses include improper input validation (CWE-20), code injection (CWE-94), and memory safety issues (CWE-119). The fix version 148.0.3967.70 addresses this vulnerability.

Defensive priority

HIGH

Recommended defensive actions

  • Update Microsoft Edge (Chromium-based) to version 148.0.3967.70 or later
  • Verify automatic update settings are enabled for Edge
  • Review browser usage policies to ensure managed deployments receive security updates
  • Monitor Microsoft Security Response Center advisories for related security updates

Evidence notes

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. CWE classifications include CWE-20 (Improper Input Validation), CWE-94 (Improper Control of Generation of Code), and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). Affected versions: Edge Chromium before 148.0.3967.70.

Official resources

This vulnerability was disclosed through official channels with vendor coordination. Microsoft published guidance via their Security Response Center.