VORANT. Threat Intelligence Sign in Get the full feed

ANSSI flags multiple Microsoft Edge vulnerabilities

elevated vulnerability

ANSSI advisory lists numerous Microsoft Edge vulnerabilities allowing privilege escalation; users should update to the latest patched versions.

ANSSI (CERT-FR) published an advisory summarizing a large batch of vulnerabilities affecting Microsoft Edge versions prior to 152.0.4191.66 and 153.0.4234.32. The advisory does not detail specific exploitation techniques but states that the vulnerabilities allow an attacker to achieve privilege escalation and cause an unspecified security issue, as characterized by the vendor. No information is provided in the advisory regarding active exploitation in the wild.

The advisory enumerates a very large number of individual CVE identifiers (well over 100), each linked to a corresponding Microsoft Security Response Center (MSRC) bulletin dated September 11 and September 14, 2026. Given the volume, defenders should prioritize patching by referring directly to the MSRC update guide entries for full technical details on each CVE, including affected components and exploitability assessments, rather than relying solely on this consolidated advisory.

Remediation is straightforward: update Microsoft Edge to version 152.0.4191.66 or later (or 153.0.4234.32 or later, depending on release channel) as soon as possible. Organizations managing Edge deployments via enterprise policy should verify update compliance across their fleet, particularly given the scale of this patch batch, which suggests a routine but substantial monthly security update cycle for the browser.

Mentioned in this report

Vulnerabilities CVE-2026-85892CVE-2026-87429CVE-2026-87430CVE-2026-87431CVE-2026-87432CVE-2026-87433CVE-2026-87434CVE-2026-87435CVE-2026-87436CVE-2026-87437CVE-2026-87439CVE-2026-87440CVE-2026-87441CVE-2026-87442CVE-2026-87443CVE-2026-87444CVE-2026-87445CVE-2026-87446CVE-2026-87447CVE-2026-87448CVE-2026-87449CVE-2026-87450CVE-2026-87451CVE-2026-87452CVE-2026-87453CVE-2026-87454CVE-2026-87455CVE-2026-87456CVE-2026-87457CVE-2026-87458CVE-2026-87459CVE-2026-87460CVE-2026-87461CVE-2026-87462CVE-2026-87463CVE-2026-87465CVE-2026-87466CVE-2026-87467CVE-2026-87468CVE-2026-87536

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1173

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free