VORANT. Threat Intelligence Sign in Get the full feed

Microsoft patches 23 Edge vulnerabilities

medium vulnerability

Microsoft released Edge 149.0.4022.96 to address 23 vulnerabilities including remote code execution flaws and unspecified security issues.

France's CERT-FR has published an advisory regarding multiple vulnerabilities discovered in Microsoft Edge browser versions prior to 149.0.4022.96. The vulnerabilities enable remote arbitrary code execution and include additional security issues not yet specified by the vendor. Microsoft released patches on June 26, 2026, addressing 23 distinct CVEs spanning the CVE-2026-11647 through CVE-2026-50521 range.

The advisory provides references to individual Microsoft Security Response Center bulletins for each CVE, allowing organizations to review technical details and apply appropriate mitigations. No active exploitation or threat actor attribution is mentioned in the French government's notification.

Organizations running affected Microsoft Edge versions should prioritize updating to version 149.0.4022.96 or later to remediate these vulnerabilities. The presence of remote code execution vectors makes timely patching important for maintaining browser security posture.

Mentioned in this report

Vulnerabilities CVE-2026-11647CVE-2026-12028CVE-2026-12030CVE-2026-12032CVE-2026-12438CVE-2026-12442CVE-2026-12448CVE-2026-12469CVE-2026-13021CVE-2026-13022CVE-2026-13023CVE-2026-13024CVE-2026-13025CVE-2026-13026CVE-2026-13027CVE-2026-13029CVE-2026-13031CVE-2026-13033CVE-2026-13034CVE-2026-13035CVE-2026-13036CVE-2026-13038CVE-2026-50521

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0811/

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free