Server-side Request Forgery Vulnerability in Microsoft Edge by Microsoft
CVE-2026-66325

6.1MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
3 August 2026

What is CVE-2026-66325?

A server-side request forgery (SSRF) vulnerability in Microsoft Edge (Chromium-based) enables unauthorized attackers to bypass security measures, allowing them to perform network spoofing. This exploitation can lead to unauthorized access and various security breaches, making it crucial for users to update their browsers and mitigate potential risks associated with this vulnerability.

Affected Version(s)

Microsoft Edge (Chromium-based) 1.0.0.0 < 151.0.4129.59

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.