CERT-FR flags multiple Microsoft Edge flaws
CERT-FR issued an advisory for multiple unspecified-impact vulnerabilities in Microsoft Edge versions before 152.0.4191.62.
CERT-FR (the French national CSIRT) published an advisory referencing 21 CVEs affecting Microsoft Edge versions prior to 152.0.4191.62. The bulletin does not detail the specific vulnerability types or exploitation vectors, stating only that the vendor has not specified the risk category and that the flaws could allow an attacker to cause an unspecified security impact. This is a standard aggregation-style advisory pointing to Microsoft's own security update guide entries for each CVE, rather than original research.
No indicators of compromise, exploitation in the wild, or threat actor attribution are mentioned. Organizations running affected Edge versions should apply the vendor-supplied patches referenced in the Microsoft Security Response Center (MSRC) update guide entries for each listed CVE. As is typical for CERT-FR advisories of this nature, the recommended action is straightforward patching rather than active threat hunting.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1116
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free