Skip to content
MicrosoftCVE-2026-57980

Microsoft Edge (Chromium-based): authentication bypass

Medium5.4CVE-2026-57980 · Published Jul 17, 2026 · updated Jul 21, 2026

Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

Microsoft advisory

Affected versions

PackageAffectedFixed in
Microsoft Edge (Chromium-based)
Product
>= 1.0.0.0, < 150.0.4078.80150.0.4078.80
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-288

More Microsoft advisories

All Microsoft
Advisory
Microsoft Windows RDP: unauthorized attacker could disclose information over
High7.1Jul 17
Microsoft Windows Admin Center: cross-site scripting
Medium6.1Jul 16
Microsoft Windows Terminal App: integer overflow
High7.5Jul 16
Microsoft Office SharePoint: cross-site scripting
Medium4.6Jul 16
Microsoft Windows Backup Engine: race condition
High7.0Jul 16
Secret exfiltration vulnerability
HighJul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.