Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)

Multiple Vulnerabilities in Microsoft Edge prior to (TL-2026-2838), also tracked as HK GovCERT A26-10-03, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-10-02. It has no confirmed attribution, affects Microsoft Microsoft Edge (Chromium-based, Stable), references 37 CVEs (CVE-2026-85047, CVE-2026-87438, CVE-2026-87464), maps to 3 MITRE ATT&CK techniques (T1203, T1204.001, T1499.004), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2838

Threat ID
TL-2026-2838
Also known as
HK GovCERT A26-10-03
Severity
CRITICAL
CVSS
9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-10-02
Last reviewed
2026-10-02
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, education, enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
12

Hong Kong GovCERT reports 37 CVEs fixed in Microsoft Edge 154.0.4258.53 (Chromium-sourced), with potential impact including remote code execution, denial of service, information disclosure, security restriction bypass, spoofing and tampering. No in-the-wild exploitation is reported; users should update to 154.0.4258.53 or later.

How Multiple Vulnerabilities in Microsoft Edge prior to works

On 2026-10-02 Hong Kong GovCERT published Security Alert A26-10-03 covering multiple vulnerabilities in Microsoft Edge prior to version 154.0.4258.53. The advisory lists 37 CVE identifiers (CVE-2026-85047, CVE-2026-87438, CVE-2026-87464, CVE-2026-87481 to -87483, -87486, -87488, -87503, -87517, -87518, -87520, -87522, -87534, -87545, -87552, -87555, -87576, -87595, -87597, -87640, -87643, CVE-2026-93372 to -93383 and CVE-2026-93385 to -93387) and states that successful exploitation could lead to remote code execution, denial of service, information disclosure, security restriction bypass, spoofing or tampering. The recommended action is to update Microsoft Edge to 154.0.4258.53 or later.

Microsoft's Edge security release notes show 154.0.4258.53 (Stable) was released 2026-10-01, after 154.0.4258.48 on 2026-09-29, and that it incorporates the latest Chromium security updates. At the time of the notes, no CVEs were yet listed for that build and no zero-day or exploited-in-the-wild flag was noted; Microsoft points to the Security Update Guide for CVE detail.

NVD records for a sample of the listed CVEs show they are Chromium/Google Chrome issues whose NVD descriptions are scoped to Chrome fixed versions 152.0.7977.82, 153.0.8010.36 and 153.0.8010.52 (several on Android or iOS). Examples: CVE-2026-85047 (improper input validation in Transactions Platform, Chrome iOS < 152.0.7977.82, CWE-20, CVSS 9.6, sandbox escape via crafted HTML page); CVE-2026-87438 (out-of-bounds write in WebGL, Chrome Android < 153.0.8010.36, CWE-787, CVSS 9.6); CVE-2026-87464 (use-after-free in WebGL, Chrome < 153.0.8010.36, CWE-416, CVSS 9.6); CVE-2026-93372 (WebGL buffer overflow, Chrome Android < 153.0.8010.52, CWE-121, CVSS 9.6); CVE-2026-87517 (race condition origin-policy bypass, iOS, CVSS 3.1); CVE-2026-87545 (information disclosure, iOS Mobile component, CWE-200, CVSS 6.5); CVE-2026-87640 (out-of-bounds read in WebView, Android, CWE-125, CVSS 6.1); CVE-2026-93380 (FileSystem race condition by a compromised renderer, CWE-367, CVSS 3.1). Only a subset of the 37 CVEs was individually checked; the rest are taken from the GovCERT list. The severity mix is wide, from Low to Critical.

None of the sampled CVEs appear in the CISA Known Exploited Vulnerabilities catalog. The KEV feed does contain two September 2026 Chromium V8 entries (CVE-2026-87491, CVE-2026-85046) that are not in this advisory's CVE list. Chrome 154 itself shipped on 2026-09-22 (154.0.8037.57/.58) with 108 security fixes, 11 rated Critical, mainly in ANGLE, GPU and WebGL; those CVE ids (e.g. CVE-2026-95350) are distinct from this advisory's list. The advisory contains no network IOCs, malware or actor attribution, so the IOC set here consists of affected product, version and component indicators for exposure and patch-compliance hunting.

MITRE ATT&CK techniques used in TL-2026-2838

Execution

T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link

Impact

T1499.004 Endpoint Denial of Service: Application or System Exploitation

Affected products and versions in Multiple Vulnerabilities in Microsoft Edge prior to

  • Microsoft — Microsoft Edge (Chromium-based, Stable)
    Vulnerable versions: prior to 154.0.4258.53
    Fixed in: 154.0.4258.53
  • Google — Chromium / Google Chrome (upstream source of the CVEs per NVD)
    Vulnerable versions: prior to 152.0.7977.82 (CVE-2026-85047, iOS); prior to 153.0.8010.36; prior to 153.0.8010.52 (CVE-2026-93372, CVE-2026-93380)
    Fixed in: 152.0.7977.82; 153.0.8010.36; 153.0.8010.52

Remediation for Multiple Vulnerabilities in Microsoft Edge prior to

Patches

  • Microsoft Edge Stable 154.0.4258.53 (released 2026-10-01)

Immediate actions

  • Update Microsoft Edge to 154.0.4258.53 or later on all endpoints
  • Restart Edge after the update so the patched build is loaded

Workarounds

  • No vendor workaround stated in the advisory; patching is the recommended action

Longer-term hardening

  • Enforce Edge auto-update and monitor browser version compliance in endpoint inventory
  • Track Microsoft Security Update Guide and Chrome Releases for Chromium-sourced fixes

CVEs associated with Multiple Vulnerabilities in Microsoft Edge prior to

  • CVE-2026-85047
  • CVE-2026-87438
  • CVE-2026-87464
  • CVE-2026-87481
  • CVE-2026-87482
  • CVE-2026-87483
  • CVE-2026-87486
  • CVE-2026-87488
  • CVE-2026-87503
  • CVE-2026-87517
  • CVE-2026-87518
  • CVE-2026-87520
  • CVE-2026-87522
  • CVE-2026-87534
  • CVE-2026-87545
  • CVE-2026-87552
  • CVE-2026-87555
  • CVE-2026-87576
  • CVE-2026-87595
  • CVE-2026-87597
  • CVE-2026-87640
  • CVE-2026-87643
  • CVE-2026-93372
  • CVE-2026-93373
  • CVE-2026-93374
  • CVE-2026-93375
  • CVE-2026-93376
  • CVE-2026-93377
  • CVE-2026-93378
  • CVE-2026-93379
  • CVE-2026-93380
  • CVE-2026-93381
  • CVE-2026-93382
  • CVE-2026-93383
  • CVE-2026-93385
  • CVE-2026-93386
  • CVE-2026-93387

Weaknesses (CWE) in Multiple Vulnerabilities in Microsoft Edge prior to

CWE-20, CWE-121, CWE-125, CWE-200, CWE-367, CWE-416, CWE-787

Timeline of Multiple Vulnerabilities in Microsoft Edge prior to

  • Edge 152.0.4191.62 released fixing CVE-2026-85046, flagged exploited in the wild; this CVE is NOT in the A26-10-03 list.
  • Edge 152.0.4191.66 released fixing CVE-2026-87491 (exploited in the wild) and Edge-specific CVE-2026-85892; neither is in the A26-10-03 list.
  • Chrome 153 reaches Stable (153.0.8010.36/.37) with 230 security fixes, five rated Critical (four in WebGL, one in Cast); the WebGL fixes align with the Chromium-sourced CVEs in this advisory.
  • Microsoft Edge Stable 153.0.4234.32 released with the Chromium 153 security updates.
  • Chrome 154 reaches Stable (154.0.8037.57/.58) with 108 security fixes, 11 rated Critical (ANGLE, GPU, WebGL); no in-the-wild exploitation reported.
  • Microsoft Edge Stable 154.0.4258.37 released, the first Edge 154 build, with the latest Chromium security updates.
  • Chrome 154 follow-up update (154.0.8037.92/.93) reported to fix 32 more security issues including a Critical ANGLE buffer overflow (CVE-2026-102331); not in this advisory's CVE list.
  • Microsoft Edge Stable 154.0.4258.48 released, the build preceding 154.0.4258.53.
  • Microsoft releases Edge Stable 154.0.4258.53 incorporating the latest Chromium security updates; release notes list no CVEs yet and no exploited-in-the-wild flag.
  • Hong Kong GovCERT publishes Security Alert A26-10-03 listing 37 CVEs fixed in Edge 154.0.4258.53 and urging users to update.

Sources cited for Multiple Vulnerabilities in Microsoft Edge prior to

More in vulnerability

Detection coverage for TL-2026-2838

As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2838 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats