← All briefings

Microsoft Edge

Date: 2026-07-27 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

No new CISA KEV entries, BSI WID advisories, or CERT-EU publications were recorded in the last 24 hours. The most notable new items are two Microsoft Edge information-disclosure vulnerabilities and active scanning activity targeting ESAFENET CDG document management systems. Previously reported critical items — including the unpatched Fastjson 1.x RCE (CVE-2026-16723) and the GitLab authenticated RCE PoC — remain the highest-priority remediation actions.


Critical Vulnerabilities

CVE-2026-57989 / CVE-2026-57990 — Microsoft Edge (Chromium-based)

  • Severity: CVSS 7.4 (both)
  • EPSS: 0 (newly published)
  • Technical detail: Two separate information-disclosure flaws in Microsoft Edge. CVE-2026-57989 is an origin validation error allowing an unauthenticated network attacker to disclose information across origins. CVE-2026-57990 involves files or directories accessible to external parties, enabling network-based information disclosure. CVE-2026-57989 affects versions below 150.0.4078.99; CVE-2026-57990 version bounds are unspecified. Both are network-exploitable without authentication, though impact is limited to information disclosure rather than code execution.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Update Microsoft Edge to version 150.0.4078.99 or later. Verify managed browser deployments via Intune or Group Policy.

ONGOING:

  • CVE-2026-16723 (Fastjson 1.x): actively exploited unpatched RCE; migrate to Fastjson 2.x immediately.
  • GitLab self-managed authenticated RCE (PoC public): apply 2026-06-10 patch; audit Jupyter notebook activity.
  • Certighost (ADCS domain controller impersonation): working public exploit; audit certificate templates, monitor DCSync events.
  • Redis (multiple CVEs, 6.2–8.8): public PoC; upgrade to 6.2.23 / 7.2.15 / 7.4.10.
  • CVE-2026-15962 (Fluent Forms Pro ≤6.2.6): PHP Object Injection; update to ≥6.2.7.
  • CVE-2026-66374 (Knot Resolver DoQ): heap overflow; upgrade to 6.4.1 or disable DoQ listener.
  • CVE-2026-66012 (SiYuan): CVSS 10.0 missing authorization; upgrade to v3.7.2.
  • CVE-2026-0257 (PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing; patch immediately.
  • CVE-2026-6875 (ServiceNow AI Platform): exploitation continues; patch and restrict access.
  • CVE-2026-6516 (ManageEngine ADAudit Plus): unauthenticated RCE; upgrade to build 8606.
  • CVE-2026-16232 (Check Point SmartConsole): KEV deadline passed — treat unpatched as compromised.
  • CVE-2026-50522 (SharePoint): KEV deadline passed — conduct compromise assessment.

European Advisories

No new BSI WID or CERT-EU advisories were published in the last 24 hours.

Previously reported advisories for JetBrains IDEs, Google Chrome, cPanel/WHM, CyberPanel, and the Microsoft Azure CVSS 10.0 cluster remain actionable — apply vendor patches per prior guidance.


Active Threats and Campaigns

NEW — ESAFENET CDG Active Scanning: SANS ISC reports ongoing reconnaissance scanning targeting ESAFENET CDG (Content Data Guard) document management systems, which are known to suffer from SQL injection, XSS, and default credential weaknesses. Scanning activity has intensified following prior public disclosure of XSS vulnerabilities. CDG is primarily deployed in Chinese-market environments but may appear in multinational organizations. Organizations running CDG should change default credentials immediately, restrict management interface exposure, and review logs for SQL injection attempts.

ONGOING — SourTrade Malvertising (In-Browser Malware Assembly): No new technical developments; block malicious domains at DNS/proxy and monitor for Bun runtime abuse.

ONGOING — Clop Targeting PTC Windchill/FlexPLM: No new developments; restrict internet exposure and investigate for data exfiltration indicators.

ONGOING — BlueNoroff Zoom/Teams Phishing Kit: No new developments; verify videoconferencing invitations and enforce MFA.

ONGOING — UAC-0099 Fake Notepad++ Plugin (MATCHBOIL.V2): No new developments; block unsigned Notepad++ plugins.

ONGOING — Steam ClickFix Cryptominer Campaign: No new developments; enforce application allowlisting.


Security News and Context

  • Google Threat Intelligence Group unified naming taxonomy: GTIG has begun rolling out a merged naming schema consolidating Mandiant and Google TAG threat actor tracking systems. Expect actor name changes in vendor reporting; update internal TIP mappings accordingly. (Google/Mandiant)
  • GitHub/PyPI time-based supply chain defenses: Both platforms have introduced time-based mechanisms in Dependabot to limit the blast radius of supply chain attacks, reducing the window for dependency confusion and typosquatting exploitation. (Bleeping Computer)
  • ShinyHunters sextortion campaign: Threat actors continue leveraging ShinyHunters breach data to send targeted $2,000 Bitcoin sextortion emails; brief staff to disregard and report. (Bleeping Computer)

  1. Microsoft Edge (CVE-2026-57989 / CVE-2026-57990): Update to ≥150.0.4078.99 across all managed endpoints; verify via Intune or Group Policy.
  2. ESAFENET CDG: Change default credentials immediately; restrict management interface to internal networks; review logs for SQL injection and XSS exploitation attempts.
  3. Fastjson 1.x (CVE-2026-16723): Migrate to Fastjson 2.x or alternative library; apply WAF rules; treat exposed instances as potentially compromised.
  4. GitLab self-managed: Confirm 2026-06-10 patch is applied; audit logs for anomalous Jupyter notebook commits and diff views.
  5. GTIG naming taxonomy change: Update threat intelligence platform actor mappings to align with new GTIG unified naming schema.
  6. ShinyHunters sextortion: Brief staff to disregard and report $2,000 Bitcoin extortion emails; no system-level action required.
  7. Supply chain hygiene: Review Dependabot configurations on GitHub and PyPI-dependent projects to leverage new time-based defenses.
  8. Continue remediation of previously reported items: Certighost (ADCS), Redis RCE, Knot Resolver (CVE-2026-66374), Fluent Forms Pro (CVE-2026-15962), SiYuan (CVE-2026-66012), PAN-OS (CVE-2026-0257), ServiceNow (CVE-2026-6875), ManageEngine (CVE-2026-6516), Check Point SmartConsole (CVE-2026-16232 — treat as compromised), SharePoint (CVE-2026-50522 — compromise assessment).