ANSSI Flags Multiple Microsoft Edge Vulnerabilities
ANSSI advisory lists numerous Microsoft Edge vulnerabilities allowing remote code execution, data confidentiality and integrity breaches; patching is advised.
ANSSI (CERT-FR) issued advisory CERTFR-2026-AVI-1096 detailing a large batch of vulnerabilities affecting Microsoft Edge, including versions prior to 150.0.4078.50 for iOS, 150.0.4078.65, and 152.0.4191.53. The vulnerabilities collectively allow an attacker to achieve remote code execution, breach data confidentiality, breach data integrity, and bypass security policies. The advisory does not specify exploitation in the wild and the editor has not specified further technical details beyond the enumerated CVE identifiers.
The bulletin references over 200 individual CVE entries, all dated 28 August 2026, each linking to Microsoft's MSRC update guide for details. No specific exploit chain, indicators of compromise, or attributed threat actor are provided in the source. Defenders should treat this as a routine but large-scale browser patch cycle and prioritize updating affected Edge installations to the versions specified in the remediation section to mitigate the range of RCE, confidentiality, and integrity risks described.
Given the volume of CVEs, organizations should apply the vendor's cumulative update promptly, particularly for Edge deployments handling sensitive data or exposed to untrusted web content. No active exploitation is confirmed in this advisory, and severity should be assessed per environment based on Edge's role in the browsing stack.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1096
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free