# ANSSI Flags Multiple Microsoft Edge Vulnerabilities

Published: 2026-08-31 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/95928ece-8a0c-5427-84ea-13b99555fb34/anssi-flags-multiple-microsoft-edge-vulnerabilities

> ANSSI advisory lists numerous Microsoft Edge vulnerabilities allowing remote code execution, data confidentiality and integrity breaches; patching is advised.

ANSSI (CERT-FR) issued advisory CERTFR-2026-AVI-1096 detailing a large batch of vulnerabilities affecting Microsoft Edge, including versions prior to 150.0.4078.50 for iOS, 150.0.4078.65, and 152.0.4191.53. The vulnerabilities collectively allow an attacker to achieve remote code execution, breach data confidentiality, breach data integrity, and bypass security policies. The advisory does not specify exploitation in the wild and the editor has not specified further technical details beyond the enumerated CVE identifiers.

The bulletin references over 200 individual CVE entries, all dated 28 August 2026, each linking to Microsoft's MSRC update guide for details. No specific exploit chain, indicators of compromise, or attributed threat actor are provided in the source. Defenders should treat this as a routine but large-scale browser patch cycle and prioritize updating affected Edge installations to the versions specified in the remediation section to mitigate the range of RCE, confidentiality, and integrity risks described.

Given the volume of CVEs, organizations should apply the vendor's cumulative update promptly, particularly for Edge deployments handling sensitive data or exposed to untrusted web content. No active exploitation is confirmed in this advisory, and severity should be assessed per environment based on Edge's role in the browsing stack.

## Mentioned in this report

- Vulnerabilities: CVE-2026-58616, CVE-2026-62904, CVE-2026-66323, CVE-2026-66324, CVE-2026-66798, CVE-2026-70309, CVE-2026-70331, CVE-2026-72984, CVE-2026-78891, CVE-2026-78892, CVE-2026-78893, CVE-2026-78894, CVE-2026-78895, CVE-2026-78896, CVE-2026-78897, CVE-2026-78898, CVE-2026-78899, CVE-2026-78900, CVE-2026-78901, CVE-2026-78903, CVE-2026-78904, CVE-2026-78905, CVE-2026-78906, CVE-2026-78907, CVE-2026-78908, CVE-2026-78909, CVE-2026-78910, CVE-2026-78911, CVE-2026-78912, CVE-2026-78913, CVE-2026-78914, CVE-2026-78915, CVE-2026-78934, CVE-2026-78938, CVE-2026-78939, CVE-2026-78940, CVE-2026-78941, CVE-2026-78942, CVE-2026-78943, CVE-2026-78944

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1096

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/95928ece-8a0c-5427-84ea-13b99555fb34/anssi-flags-multiple-microsoft-edge-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
