CVE-2026-66323
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C
- EPSS probability
- 0.29%
- CWE
- CWE-141
- Published
- 2026-08-28
- Last modified
- 2026-09-03
Affected products
- Microsoft Microsoft Edge (Chromium-based)
Weakness type
Related vulnerabilities
- CVE-2026-19594 — Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation
- CVE-2026-20200 — Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
- CVE-2026-56813 — Cookie attribute injection in Plug.Conn.Cookies.encode/2
- CVE-2025-20338 — A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker...
- CVE-2025-31329 — Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
- CVE-2024-0840 — Grandstream UCM Series IP PBX HTTP Parameter Injection
- CVE-2022-41665 — A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10),...
- CVE-2022-29873 — A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not...