Changeflow GovPing Data Privacy & Cybersecurity Edge Vulnerability Allows File Manipulation, In...
Routine Notice Added Final

Edge Vulnerability Allows File Manipulation, Information Disclosure

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published
Detected
Email

Summary

CERT-Bund issued a security advisory about a vulnerability in Microsoft Edge (versions prior to 146.0.3856.84) with a CVSS Base Score of 4.2 (medium). The vulnerability allows remote anonymous attackers to manipulate files and disclose confidential information. Users are advised to update to the patched version.

Published by CERT-Bund on wid.cert-bund.de . Detected, standardized, and enriched by GovPing. Review our methodology and editorial standards .

What changed

CERT-Bund published advisory WID-SEC-2026-0905 disclosing a vulnerability in Microsoft Edge affecting versions before 146.0.3856.84. The vulnerability enables remote, anonymous attackers to exploit the browser to manipulate files and disclose confidential information. This is classified as a medium-severity issue with CVSS Base Score 4.2 and temporal score 3.7.

Organizations and individual users running affected Microsoft Edge versions should update to version 146.0.3856.84 or later immediately. Security teams should review patch management procedures and prioritize applying this update according to organizational vulnerability management policies.

What to do next

  1. Update Microsoft Edge to version 146.0.3856.84 or later
  2. Review and apply updates through organizational patch management procedures
  3. Assess exposure of sensitive files to potential exploitation

Archived snapshot

Mar 30, 2026

GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.

[WID-SEC-2026-0905] Microsoft Edge: Schwachstelle ermöglicht Manipulation von Dateien und die Offenlegung von Informationen CVSS Base Score 4.2 (mittel) CVSS Temporal Score 3.7 (niedrig) Remoteangriff ja Datum 29.03.2026 Stand 30.03.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Windows

Produktbeschreibung

Edge ist ein Web Browser von Microsoft.

Produkte

29.03.2026
- Microsoft Edge <146.0.3856.84

Angriff

Angriff

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Microsoft Edge ausnutzen, um Dateien zu manipulieren und vertrauliche Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Get daily alerts for CERT-Bund Security Advisories

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

About this page

What is GovPing?

Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission

What's from the agency?

Source document text, dates, docket IDs, and authority are extracted directly from CERT-Bund.

What's AI-generated?

The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.

Last updated

Classification

Agency
CERT-Bund
Published
March 29th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Minor
Document ID
WID-SEC-2026-0905

Who this affects

Applies to
Consumers Government agencies Technology companies
Industry sector
5112 Software & Technology
Activity scope
Software Patching Browser Security
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Data Privacy

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.

You're subscribed!