CERT-FR Warns of Microsoft Edge Vulnerabilities
CERT-FR advisory details two Microsoft Edge vulnerabilities allowing remote code execution and privilege escalation, fixed in version 153.0.4234.32.
CERT-FR published an advisory covering multiple vulnerabilities in Microsoft Edge versions prior to 153.0.4234.32. The two disclosed CVEs, CVE-2026-69486 and CVE-2026-85893, could allow an attacker to achieve remote code execution and privilege escalation. Microsoft published corresponding security bulletins on 15 September 2026.
No evidence of active exploitation is mentioned in the advisory. Defenders should apply the vendor-supplied update to bring Microsoft Edge to version 153.0.4234.32 or later, following the guidance in Microsoft's security bulletins referenced in the advisory.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1191
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free