CVE-2026-58289 EXPLOIT
9.0
CRITICAL · CVSS 3.1 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Scoring
| CVSS | 9.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 1.99% — more likely to be exploited than 80% of all CVEs |
| Weakness | CWE-843 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2026-07-03 |
| Last modified | 2026-07-07 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | edge chromium |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Edge 150.0.4078.48 - RCE | 2026-08-10 |
→ the Explorer · watch your stack · NVD