Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)
Multiple Vulnerabilities in Microsoft Edge prior to (TL-2026-2838), also tracked as HK GovCERT A26-10-03, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-10-02. It has no confirmed attribution, affects Microsoft Microsoft Edge (Chromium-based, Stable), references 37 CVEs (CVE-2026-85047, CVE-2026-87438, CVE-2026-87464), maps to 3 MITRE ATT&CK techniques (T1203, T1204.001, T1499.004), and is covered by 9 detection rules and 12 indicators of compromise.
Key facts for TL-2026-2838
- Threat ID
- TL-2026-2838
- Also known as
- HK GovCERT A26-10-03
- Severity
- CRITICAL
- CVSS
- 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-10-02
- Last reviewed
- 2026-10-02
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, education, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
Hong Kong GovCERT reports 37 CVEs fixed in Microsoft Edge 154.0.4258.53 (Chromium-sourced), with potential impact including remote code execution, denial of service, information disclosure, security restriction bypass, spoofing and tampering. No in-the-wild exploitation is reported; users should update to 154.0.4258.53 or later.
How Multiple Vulnerabilities in Microsoft Edge prior to works
On 2026-10-02 Hong Kong GovCERT published Security Alert A26-10-03 covering multiple vulnerabilities in Microsoft Edge prior to version 154.0.4258.53. The advisory lists 37 CVE identifiers (CVE-2026-85047, CVE-2026-87438, CVE-2026-87464, CVE-2026-87481 to -87483, -87486, -87488, -87503, -87517, -87518, -87520, -87522, -87534, -87545, -87552, -87555, -87576, -87595, -87597, -87640, -87643, CVE-2026-93372 to -93383 and CVE-2026-93385 to -93387) and states that successful exploitation could lead to remote code execution, denial of service, information disclosure, security restriction bypass, spoofing or tampering. The recommended action is to update Microsoft Edge to 154.0.4258.53 or later.
Microsoft's Edge security release notes show 154.0.4258.53 (Stable) was released 2026-10-01, after 154.0.4258.48 on 2026-09-29, and that it incorporates the latest Chromium security updates. At the time of the notes, no CVEs were yet listed for that build and no zero-day or exploited-in-the-wild flag was noted; Microsoft points to the Security Update Guide for CVE detail.
NVD records for a sample of the listed CVEs show they are Chromium/Google Chrome issues whose NVD descriptions are scoped to Chrome fixed versions 152.0.7977.82, 153.0.8010.36 and 153.0.8010.52 (several on Android or iOS). Examples: CVE-2026-85047 (improper input validation in Transactions Platform, Chrome iOS < 152.0.7977.82, CWE-20, CVSS 9.6, sandbox escape via crafted HTML page); CVE-2026-87438 (out-of-bounds write in WebGL, Chrome Android < 153.0.8010.36, CWE-787, CVSS 9.6); CVE-2026-87464 (use-after-free in WebGL, Chrome < 153.0.8010.36, CWE-416, CVSS 9.6); CVE-2026-93372 (WebGL buffer overflow, Chrome Android < 153.0.8010.52, CWE-121, CVSS 9.6); CVE-2026-87517 (race condition origin-policy bypass, iOS, CVSS 3.1); CVE-2026-87545 (information disclosure, iOS Mobile component, CWE-200, CVSS 6.5); CVE-2026-87640 (out-of-bounds read in WebView, Android, CWE-125, CVSS 6.1); CVE-2026-93380 (FileSystem race condition by a compromised renderer, CWE-367, CVSS 3.1). Only a subset of the 37 CVEs was individually checked; the rest are taken from the GovCERT list. The severity mix is wide, from Low to Critical.
None of the sampled CVEs appear in the CISA Known Exploited Vulnerabilities catalog. The KEV feed does contain two September 2026 Chromium V8 entries (CVE-2026-87491, CVE-2026-85046) that are not in this advisory's CVE list. Chrome 154 itself shipped on 2026-09-22 (154.0.8037.57/.58) with 108 security fixes, 11 rated Critical, mainly in ANGLE, GPU and WebGL; those CVE ids (e.g. CVE-2026-95350) are distinct from this advisory's list. The advisory contains no network IOCs, malware or actor attribution, so the IOC set here consists of affected product, version and component indicators for exposure and patch-compliance hunting.
MITRE ATT&CK techniques used in TL-2026-2838
Execution
T1203 Exploitation for Client Execution; T1204.001 User Execution: Malicious Link
Impact
T1499.004 Endpoint Denial of Service: Application or System Exploitation
Affected products and versions in Multiple Vulnerabilities in Microsoft Edge prior to
- Microsoft — Microsoft Edge (Chromium-based, Stable)
Vulnerable versions: prior to 154.0.4258.53
Fixed in: 154.0.4258.53 - Google — Chromium / Google Chrome (upstream source of the CVEs per NVD)
Vulnerable versions: prior to 152.0.7977.82 (CVE-2026-85047, iOS); prior to 153.0.8010.36; prior to 153.0.8010.52 (CVE-2026-93372, CVE-2026-93380)
Fixed in: 152.0.7977.82; 153.0.8010.36; 153.0.8010.52
Remediation for Multiple Vulnerabilities in Microsoft Edge prior to
Patches
- Microsoft Edge Stable 154.0.4258.53 (released 2026-10-01)
Immediate actions
- Update Microsoft Edge to 154.0.4258.53 or later on all endpoints
- Restart Edge after the update so the patched build is loaded
Workarounds
- No vendor workaround stated in the advisory; patching is the recommended action
Longer-term hardening
- Enforce Edge auto-update and monitor browser version compliance in endpoint inventory
- Track Microsoft Security Update Guide and Chrome Releases for Chromium-sourced fixes
CVEs associated with Multiple Vulnerabilities in Microsoft Edge prior to
- CVE-2026-85047
- CVE-2026-87438
- CVE-2026-87464
- CVE-2026-87481
CVE-2026-87482CVE-2026-87483CVE-2026-87486CVE-2026-87488CVE-2026-87503CVE-2026-87517CVE-2026-87518CVE-2026-87520CVE-2026-87522CVE-2026-87534CVE-2026-87545CVE-2026-87552CVE-2026-87555CVE-2026-87576CVE-2026-87595CVE-2026-87597CVE-2026-87640CVE-2026-87643CVE-2026-93372CVE-2026-93373CVE-2026-93374CVE-2026-93375CVE-2026-93376CVE-2026-93377CVE-2026-93378CVE-2026-93379CVE-2026-93380CVE-2026-93381CVE-2026-93382CVE-2026-93383CVE-2026-93385CVE-2026-93386CVE-2026-93387
Weaknesses (CWE) in Multiple Vulnerabilities in Microsoft Edge prior to
CWE-20, CWE-121, CWE-125, CWE-200, CWE-367, CWE-416, CWE-787
Timeline of Multiple Vulnerabilities in Microsoft Edge prior to
- Edge 152.0.4191.62 released fixing CVE-2026-85046, flagged exploited in the wild; this CVE is NOT in the A26-10-03 list.
- Edge 152.0.4191.66 released fixing CVE-2026-87491 (exploited in the wild) and Edge-specific CVE-2026-85892; neither is in the A26-10-03 list.
- Chrome 153 reaches Stable (153.0.8010.36/.37) with 230 security fixes, five rated Critical (four in WebGL, one in Cast); the WebGL fixes align with the Chromium-sourced CVEs in this advisory.
- Microsoft Edge Stable 153.0.4234.32 released with the Chromium 153 security updates.
- Chrome 154 reaches Stable (154.0.8037.57/.58) with 108 security fixes, 11 rated Critical (ANGLE, GPU, WebGL); no in-the-wild exploitation reported.
- Microsoft Edge Stable 154.0.4258.37 released, the first Edge 154 build, with the latest Chromium security updates.
- Chrome 154 follow-up update (154.0.8037.92/.93) reported to fix 32 more security issues including a Critical ANGLE buffer overflow (CVE-2026-102331); not in this advisory's CVE list.
- Microsoft Edge Stable 154.0.4258.48 released, the build preceding 154.0.4258.53.
- Microsoft releases Edge Stable 154.0.4258.53 incorporating the latest Chromium security updates; release notes list no CVEs yet and no exploited-in-the-wild flag.
- Hong Kong GovCERT publishes Security Alert A26-10-03 listing 37 CVEs fixed in Edge 154.0.4258.53 and urging users to update.
Sources cited for Multiple Vulnerabilities in Microsoft Edge prior to
- HK GovCERT Security Alert (A26-10-03): Multiple Vulnerabilities in Microsoft Edge
- Microsoft Edge Release Notes (Security) - October 01, 2026
- Microsoft Security Update Guide
- NVD - CVE-2026-85047
- NVD - CVE-2026-87438
- NVD - CVE-2026-93372
- CISA Known Exploited Vulnerabilities Catalog
- Chrome Releases - Stable Channel Update for Desktop
- Update Chrome: 108 security fixes for desktop, new release for Android (Malwarebytes)
- Chrome 153 Stable Arrives With 230 Security Fixes
- Google Chrome 154 Fixes 108 Security Flaws: 11 Are Rated Critical (TechRepublic)
More in vulnerability
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)
- GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)
- CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD
- Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on Firmware 7.00-13.60
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild
Detection coverage for TL-2026-2838
As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2838 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.