Microsoft released a security update for Microsoft Edge (Chromium-based) to remediate a high-severity remote code execution vulnerability tracked as CVE-2026-50521. According to the advisory, the flaw carries a CVSS score of 8.3 and could allow a remote attacker to execute arbitrary code over a network.
The vulnerability was described as having low attack complexity, requiring low privileges and no user interaction, increasing the urgency for enterprise remediation. Microsoft documented the fix in its Edge security release notes, and external defenders including EG-FinCIRT urged organizations to deploy the update promptly after standard testing to reduce exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft released a security update for Microsoft Edge (Chromium-based) on June 28, 2026 to fix CVE-2026-50521, a remote code execution vulnerability. The flaw was described as network-exploitable with low attack complexity, low privileges required, and no user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.