CVE-2026-65804: Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published Jul 31, 2026
·Updated
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Other sources
Microsoft Edge (Chromium-based) Spoofing Vulnerability
— Microsoft
Affected Software
3 affected componentsFixes available
Microsoft Edge (Chromium-based)<151.0.4129.59
151.0.4129.59
Microsoft Edge<151.0.4129.59
Microsoft Edge Chromium<151.0.4129.59
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.59
Event History
Jul 31, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
DescriptionAffected Software
Aug 3, 2026
CVE Published
via MITRE·10:57 PM
Data Sourced
via MITRE·10:57 PM
DescriptionSeverity
Aug 4, 2026
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-65804?
CVE-2026-65804 has a medium severity score of 6.1.
2
What type of vulnerability is CVE-2026-65804?
CVE-2026-65804 is a spoofing vulnerability stemming from improper control of code generation.
3
How do I fix CVE-2026-65804?
To fix CVE-2026-65804, ensure that you update to the latest version of Microsoft Edge.
4
What software is affected by CVE-2026-65804?
CVE-2026-65804 affects Microsoft Edge (Chromium-based) software.
5
Can CVE-2026-65804 be exploited remotely?
Yes, CVE-2026-65804 can be exploited over a network by an unauthorized attacker.