DIRAS TAKE
Urgent: this is a critical, network-accessible bypass that requires no authentication; update Microsoft Edge to build 150.0.4078.48 immediately where possible.
What is CVE-2026-57983?
An unauthenticated remote attacker can bypass a security feature in Microsoft Edge (Chromium-based), allowing unauthorized actions against the browser. This is tracked as CVE-2026-57983. The issue affects Microsoft Edge 150.x versions from 1.0.0.0 up to, but not including, 150.0.4078.48; the vendor lists a fixed build of 150.0.4078.48. Exploitation requires only network access and no valid user credentials or interaction, per the vendor description and the CVSS vector values.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Which versions of Microsoft Microsoft Edge (Chromium-based) are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 150.x | 1.0.0.0 – before 150.0.4078.48 | 150.0.4078.48 |
Is CVE-2026-57983 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-57983
- Update Microsoft Edge to the fixed release 150.0.4078.48.
- If you cannot update immediately, restrict network exposure of affected endpoints and block untrusted network sources.
- Apply vendor guidance and enterprise update policies to roll out the fixed build to all managed devices.
- Monitor browser logs and network telemetry for unusual or unauthorized activity related to Edge processes.
Frequently asked questions
Is CVE-2026-57983 being actively exploited?
There are no public reports of exploitation of CVE-2026-57983 as of 2026-09-29.
Which Microsoft Edge versions are affected by CVE-2026-57983?
Microsoft Edge (Chromium-based) branch 150.x versions from 1.0.0.0 up to, but not including, 150.0.4078.48 are affected.
Is there a patch for CVE-2026-57983?
Yes. Microsoft lists a fixed build: 150.0.4078.48.
Does CVE-2026-57983 require authentication?
No. The vulnerability allows an unauthenticated attacker with network access to bypass a security feature without valid credentials or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-57983
- cve.org/CVERecord?id=CVE-2026-57983
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57983
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026