# Microsoft Edge multiple vulnerabilities remote code execution

Published: 2026-07-07 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/93643fdf-96b0-51b4-b29b-bf9045ea2003/microsoft-edge-multiple-vulnerabilities-remote-code-execution

> CERT-FR advisory on 200+ CVEs in Microsoft Edge below version 150.0.4078.48, permitting remote code execution, privilege escalation, and data exfiltration; immediate patching required.

CERT-FR has published an advisory covering multiple vulnerabilities discovered in Microsoft Edge versions prior to 150.0.4078.48. The flaws span a broad range of impact categories including remote code execution, privilege escalation, data confidentiality breaches, SSRF, XSS, and security policy bypass. Microsoft Edge users running affected versions face risk of arbitrary code execution and unauthorized system access if a malicious actor exploits these weaknesses. The advisory references individual Microsoft Security Response Center (MSRC) bulletins published on 2–3 July 2026 for each CVE, directing organizations to consult the official patches. No active exploitation in the wild is reported in this advisory, but the breadth and severity of the flaws warrant immediate update to version 150.0.0.4078.48 or later.

## Mentioned in this report

- Vulnerabilities: CVE-2026-13774, CVE-2026-13775, CVE-2026-13776, CVE-2026-13779, CVE-2026-13780, CVE-2026-13781, CVE-2026-13782, CVE-2026-13783, CVE-2026-13784, CVE-2026-13786, CVE-2026-13787, CVE-2026-13790, CVE-2026-13793, CVE-2026-13794, CVE-2026-13796, CVE-2026-13797, CVE-2026-13798, CVE-2026-13799, CVE-2026-13800, CVE-2026-13801, CVE-2026-13802, CVE-2026-13803, CVE-2026-13804, CVE-2026-13806, CVE-2026-13810, CVE-2026-13811, CVE-2026-13814, CVE-2026-13815, CVE-2026-13817, CVE-2026-13818, CVE-2026-13820, CVE-2026-13821, CVE-2026-13823, CVE-2026-13824, CVE-2026-13828, CVE-2026-13829, CVE-2026-13830, CVE-2026-13831, CVE-2026-13832, CVE-2026-57991

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0840

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/93643fdf-96b0-51b4-b29b-bf9045ea2003/microsoft-edge-multiple-vulnerabilities-remote-code-execution.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
