Aug 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-66323 Published on August 28, 2026

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Vendor Advisory NVD

Weakness Type

Improper Neutralization of Parameter/Argument Delimiters

The software receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as parameter or argument delimiters when they are sent to a downstream component. As data is parsed, an injected/absent/malformed delimiter may cause the process to take unexpected actions.


Products Associated with CVE-2026-66323

stack.watch emails you whenever new vulnerabilities are published in Microsoft Edge Chromium or Microsoft Edge Browser. Just hit a watch button to start following.

 
 

Affected Versions

Microsoft Edge for Android: Microsoft Edge for iOS: Microsoft Edge for Linux: Microsoft Edge for MAC: Microsoft Edge for Windows: