rootpwn

Vulnerabilities

Microsoft Edge Hit by Multi‑Vulnerability Storm; CVE‑2026‑87491 Under Active Exploitation

A wave of security flaws has been uncovered in Microsoft Edge, enabling attackers to bypass security policies and trigger unspecified critical issues. The most urgent flaw, CVE‑2026‑87491, is already being exploited in the wild. Versions prior to 151.0.4129.107 and 152.0.4191.66 are affected. Microsoft has issued a series of security bulletins; users must apply the latest patches immediately to close the gaps.

RootPwn’s threat intel team has flagged a cascade of vulnerabilities in Microsoft Edge that collectively allow an attacker to sidestep the browser’s security policies and trigger an undefined critical flaw. The most pressing of these, CVE‑2026‑87491, is confirmed to be actively exploited by threat actors.

Impact Overview

  • Bypasses Edge’s security policy enforcement.
  • Triggers a critical, unspecified security issue identified by Microsoft.
  • Exploits are already observed in the wild, raising the risk level to High.

Affected Edge Versions

  • All releases before 151.0.4129.107
  • All releases before 152.0.4191.66

Mitigation & Recommendations

  • Upgrade Microsoft Edge to the latest available version immediately.
  • Apply all Microsoft security patches released for Edge, particularly those addressing CVE‑2026‑76017 through CVE‑2026‑87491.
  • Verify that the policy bypass protections are active by checking the browser’s security settings.
  • Monitor network traffic for signs of exploitation attempts, such as anomalous requests to known malicious domains.
  • Consider disabling Edge’s “Allow insecure content” settings until a full patch is applied.
Microsoft’s Security Bulletin series (dated 11 September 2026) details each CVE and the corresponding fix. Users should consult the official Microsoft Update Guide for the precise patch download links.

Microsoft Edge CVE-2026-87491 Browser Exploit Active Exploitation Security Patch Policy Bypass

← All news