PULSE
LIVE65signals / 24h
FEED
← All CVEs
CVE WatchAug 4, 2026

CVE-2026-66316

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS

5.4

Medium

EPSS

0.2%

p12

KEV

Exploit Today

4

0-100

Published: Aug 4, 2026 · Last modified: Aug 4, 2026 · CWE-346

EPSS · 30d

Not enough EPSS history yet.

Technical description

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-705995.9 MED
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level frame origin to session.setPermissionCheckHandler instead of the requesting iframe origin. Origin-based handler logic could grant a cross-origin iframe device access intended only for the top-level origin. This issue is fixed in 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1.6h
CVE-2026-164427.4 HIG
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.5h
CVE-2026-15587
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability was patched with version 6.3.85, and no customer action is needed.6h
CVE-2026-663227.1 HIG
18.1%
5Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.1d
CVE-2026-663188.1 HIG
29.5%
9Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.17h
CVE-2026-663175.4 MED
12.2%
4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.1d
CVE-2026-66316 — Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize · Pulse | Pulse