PatchSiren cyber security CVE debrief
CVE-2026-45495 Microsoft CVE debrief
A remote code execution vulnerability in Microsoft Edge (Chromium-based) allows an attacker to execute arbitrary code on affected systems. The vulnerability is rated HIGH severity with a CVSS 3.1 score of 8.8, indicating significant risk due to network attack vector, low attack complexity, and no required privileges—though user interaction is required. The affected product is Microsoft Edge Chromium prior to version 148.0.3967.70. The vulnerability was published in the NVD on May 18, 2026, with subsequent modification on May 19, 2026. Microsoft has issued a vendor advisory addressing this issue. Organizations should prioritize updating Edge Chromium to version 148.0.3967.70 or later.
- Vendor
- Microsoft
- Product
- Microsoft Edge (Chromium-based)
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-18
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-18
- Advisory updated
- 2026-05-26
Who should care
Organizations using Microsoft Edge (Chromium-based) in enterprise environments, security teams responsible for browser security posture, and end users relying on Edge for web browsing should prioritize this update.
Technical summary
CVE-2026-45495 is a remote code execution vulnerability in Microsoft Edge (Chromium-based). The vulnerability can be triggered with user interaction and allows an unauthenticated attacker to execute arbitrary code with the privileges of the browser process. The CVSS 3.1 score of 8.8 reflects network accessibility, low complexity, and high impact to confidentiality, integrity, and availability. Root cause weaknesses include improper input validation (CWE-20), code injection (CWE-94), and memory safety issues (CWE-119). The fix version 148.0.3967.70 addresses this vulnerability.
Defensive priority
HIGH
Recommended defensive actions
- Update Microsoft Edge (Chromium-based) to version 148.0.3967.70 or later
- Verify automatic update settings are enabled for Edge
- Review browser usage policies to ensure managed deployments receive security updates
- Monitor Microsoft Security Response Center advisories for related security updates
Evidence notes
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. CWE classifications include CWE-20 (Improper Input Validation), CWE-94 (Improper Control of Generation of Code), and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). Affected versions: Edge Chromium before 148.0.3967.70.
Official resources
-
CVE-2026-45495 CVE record
CVE.org
-
CVE-2026-45495 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
This vulnerability was disclosed through official channels with vendor coordination. Microsoft published guidance via their Security Response Center.