CVE-2026-66323CWE-141

CVE-2026-66323

Medium · published August 29, 2026

CVSS v3.1
5.4
EPSS
0%
Percentile
21.4
In the wild
Unconfirmed
What it is

Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00292 · 21.4th percentile
Weakness
CWE-141 · Improper Neutralization of Parameter/Argument Delimiters
Published
2026-08-29T00:19Z
Affected products (1)
ProductVersionsFixed in
microsoft/edge_chromium< 152.0.4191.53152.0.4191.53
References (1)
EPSS history
Timeline
  • 30 AUG 16:19Z
    EPSS moved — → 0%
    epss
  • 28 AUG 17:45Z
    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
    cvelistv5