VORANT. Threat Intelligence Sign in Get the full feed

CERT-FR flags mass Microsoft Edge CVE batch

medium vulnerability

CERT-FR published an advisory covering over 200 vulnerabilities in Microsoft Edge and Edge for Android, patched in version 151.0.4129.59.

The French national CERT (CERT-FR) issued an advisory summarizing a large batch of vulnerabilities affecting Microsoft Edge and Microsoft Edge for Android versions prior to 151.0.4129.59. The vulnerabilities collectively enable remote code execution, data confidentiality breaches, data integrity breaches, and security policy bypass, though the advisory does not specify which individual CVEs map to which impact, nor does it indicate any in-the-wild exploitation.

This is a routine vendor patch cycle roll-up rather than a targeted campaign disclosure. Microsoft's own security bulletins (dated 31 July 2026) provide the technical detail for each CVE; CERT-FR's role here is aggregation and notification to French public and private sector entities. Organizations running affected Edge versions, particularly on Android, should apply the vendor update promptly given the volume of RCE-capable flaws bundled in this release, even absent confirmed active exploitation.

Mentioned in this report

Vulnerabilities CVE-2026-17650CVE-2026-17651CVE-2026-17652CVE-2026-17653CVE-2026-17654CVE-2026-17655CVE-2026-17656CVE-2026-17657CVE-2026-17658CVE-2026-17659

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0960

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free