PULSE
EN VIVO65señales / 24h
FEED
← Todos los CVEs
CVE Watch4 ago 2026

CVE-2026-66317

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

CVSS

5.4

Medio

EPSS

0.2%

p12

KEV

Exploit Today

4

0-100

Publicado: 4 ago 2026 · Última mod.: 4 ago 2026 · CWE-346

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-705995.9 MED
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level frame origin to session.setPermissionCheckHandler instead of the requesting iframe origin. Origin-based handler logic could grant a cross-origin iframe device access intended only for the top-level origin. This issue is fixed in 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1.7h
CVE-2026-164427.4 ALT
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.6h
CVE-2026-15587
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability was patched with version 6.3.85, and no customer action is needed.7h
CVE-2026-663227.1 ALT
18.1%
5Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.1d
CVE-2026-663188.1 ALT
29.5%
9Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.18h
CVE-2026-663165.4 MED
12.2%
4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.1d