Aug 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-66323 Published on August 28, 2026

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Vendor Advisory NVD

Weakness Type

Improper Neutralization of Parameter/Argument Delimiters

The software receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as parameter or argument delimiters when they are sent to a downstream component. As data is parsed, an injected/absent/malformed delimiter may cause the process to take unexpected actions.


Products Associated with CVE-2026-66323

Want to know whenever a new CVE is published for Microsoft Edge Chromium? stack.watch will email you.

 

Affected Versions

Microsoft Edge (Chromium-based):