Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-57990 represents a critical information disclosure vulnerability in Microsoft Edge (Chromium-based) where files or directories are accessible to unauthorized external parties over a network. This vulnerability, rated 7.4 (high) severity, stems from CWE-552 (Improper File and Directory Permissions), a foundational weakness where sensitive files lack appropriate access controls. The vulnerability affects organizations and individual users relying on Edge for browsing, potentially exposing sensitive configuration files, cached data, or user information to network-based attackers. While not yet observed in active exploitation campaigns tracked by CISA, the moderate-to-high CVSS score indicates meaningful real-world risk that organizations should address through timely patching and defensive monitoring.
Although CVE-2026-57990 does not map directly to MITRE ATT&CK techniques, Casky's AI-driven skill set enables practitioners to detect the reconnaissance and exploitation patterns that would precede or accompany this attack. Claude AI's extended reasoning capabilities can correlate unusual file access patterns, network-based enumeration attempts targeting Edge cache directories, and anomalous permission requests with potential exploitation activity. Practitioners using Casky would identify attack indicators such as T1005 (Data from Local System) when attackers attempt to exfiltrate accessible files, T1040 (Network Sniffing) if credential data is transmitted insecurely, and T1592 (Gather Victim Host Information) during reconnaissance phases. By mapping security findings against 754 mapped skills, organizations gain visibility into the attack chain—from initial discovery of misconfigured permissions through lateral movement and data exfiltration—enabling faster detection and response to exploitation attempts.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-57990. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation