CVE-2026-66318
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVSS
8.1
High
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Published: Aug 4, 2026 · Last modified: Aug 5, 2026 · CWE-346
Not enough EPSS history yet.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-705995.9 MED—
———Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level frame origin to session.setPermissionCheckHandler instead of the requesting iframe origin. Origin-based handler logic could grant a cross-origin iframe device access intended only for the top-level origin. This issue is fixed in 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1.6hCVE-2026-164427.4 HIG—
———A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.5hCVE-2026-15587——
———Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header.
This vulnerability was patched with version 6.3.85, and no customer action is needed.6hCVE-2026-663227.1 HIG18.1%
——5Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.1dCVE-2026-663175.4 MED12.2%
——4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.1dCVE-2026-663165.4 MED12.2%
——4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.1d