GovCERT.HK Security Alert A26-08-01: Multiple Vulnerabilities in Microsoft Edge, Office 2019/LTSC 2021/LTSC 2024, Excel 2016, and Microsoft 365 Apps for Enterprise — Threadlinqs Intelligence
As of 2026-08-03, GovCERT.HK Security Alert A26-08-01: Multiple Vulnerabilities in Microsoft Edge, Office 2019/LTSC 2021/LTSC 2024, Excel 2016, and Microsoft 365 Apps for Enterprise is a medium-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-1827 · Severity: MEDIUM · Status: PATCHED · Category: VULNERABILITY
GovCERT.HK published Security Alert A26-08-01 on 3 August 2026, bundling a Chromium-derived Microsoft Edge CVE range (CVE-2026-17650 through CVE-2026-18019) with a set of named Microsoft
On 3 August 2026, the Hong Kong Government Computer Emergency Response Team (GovCERT.HK) issued Security Alert A26-08-01, a routine patch-cycle bundle covering multiple Microsoft client products. The advisory groups vulnerabilities across two product families with different disclosure maturity: (1) Microsoft Edge prior to Stable Channel version 151.0.4129.59, where GovCERT.HK cites the block CVE-2026-17650 through CVE-2026-18019 — a Chromium-inherited numbering range that Microsoft's own Edge Security Release Notes had, as of the 31 July 2026 Stable release, not yet individually itemized ('CVE's will be added as soon as available'); and (2) Microsoft Office 2019, Office LTSC 2021, Office LTSC 2024, Microsoft Excel 2016, and Microsoft 365 Apps for Enterprise, covered by named CVEs CVE-2026-62870, CVE-2026-65802, CVE-2026-65804, CVE-2026-66311 through CVE-2026-66318, CVE-2026-66321, CVE-2026-66322, CVE-2026-66325, and CVE-2026-66326.
GovCERT.HK states exploitation could result in remote code execution, denial of service, information disclosure, security restriction bypass, spoofing, or tampering, without differentiating impact by individual CVE. The alert carries GovCERT.HK's standard 'Security Alert' classification rather than its elevated 'High Threat Security Alert' tier, and does not assert active exploitation, a public proof-of-concept, or CISA KEV listing. Direct NVD REST API queries during this research for CVE-2026-62870 and CVE-2026-66311 both returned zero results (empty `vulnerabilities` array), independently confirming these identifiers are reserved but not yet populated with descriptions or CVSS scores in the public record — consistent with GovCERT.HK naming them ahead of upstream vendor/NVD detail. None of the named Office/Excel CVEs appear in Microsoft's July 14, 2026 monthly Office/365 Apps security-update release (Current Channel Build 20131.20154, nor the perpetual-channel KB5002886/KB5002887 Excel/Office 2016 updates), indicating this is either an out-of-cycle Current Channel update or a set of very recently reserved/disclosed identifiers. The Edge-side CVE-2026-17650–18019 range aligns with Edge's inheritance of upstream Chromium/Chrome security fixes: Google shipped Chrome Stable security updates on 2026-07-16 (3 Critical-rated flaws) and 2026-07-21 (12 vulnerabilities across WebAudio, ANGLE, V8, Skia, Extensions, Chromecast, certificate handling, GPU, and UI) in the weeks immediately preceding Edge 151.0.4129.59's 2026-07-31 release, the normal cadence by which Chromium CVEs are re-numbered into Microsoft's own range before being individually detailed. Separately, Microsoft's July 14, 2026 Patch Tuesday was independently reported as a record-breaking cycle (570-621 CVEs, ~60-63 rated Critical, including two actively-exploited zero-days and numerous Excel RCE fixes) — none of which correspond to the CVE numbers in this bundle, but which establishes the unusually high patch volume backdrop against which A26-08-01 was issued. Remediation is straightforward: apply the Edge Stable update (151.0.4129.59 or later) and the corresponding Office/365 Apps security updates via Windows Update or the Microsoft Update Catalog.
Target sectors: government administration, all-industries
Target regions: hong kong, Global
Detections & IOCs
As of 2026-08-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, MEDIUM, threat intelligence, cybersecurity, CVE-2026-17650 - CVE-2026-18019, CVE-2026-62870, CVE-2026-65802, CVE-2026-65804, CVE-2026-66311 - CVE-2026-66318, CVE-2026-66321 - CVE-2026-66322, CVE-2026-66325 - CVE-2026-66326, T1189, T1566, T1203, T1204, T1068, T1211, T1036, T1539, T1217, T1082