# CERT-FR flags multiple Microsoft Edge vulnerabilities

Published: 2026-09-21 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/d2ec79f1-3fdf-523b-bf22-bcb9e6cce12b/cert-fr-flags-multiple-microsoft-edge-vulnerabilities

> CERT-FR advisory lists numerous Microsoft Edge vulnerabilities allowing privilege escalation and other unspecified security issues; update to 153.0.4234.46 or later.

CERT-FR published an advisory summarizing multiple vulnerabilities discovered in Microsoft Edge affecting all versions prior to 153.0.4234.46. According to the advisory, successful exploitation could allow an attacker to achieve privilege escalation, as well as an additional security issue not further specified by the vendor. No technical details, exploitation vectors, or proof-of-concept information are included in the bulletin.

The advisory references over 40 distinct CVE identifiers (CVE-2026-91708 through CVE-2026-91749, plus CVE-2026-88097), all tied to the same Microsoft Edge security bulletin dated 17-18 September 2026. There is no indication in the advisory of active exploitation in the wild. CERT-FR's guidance is straightforward: consult Microsoft's official security bulletins for each CVE and apply the vendor-supplied patches to update Edge to version 153.0.4234.46 or later.

For defenders, the practical action is to ensure Microsoft Edge is updated across the estate via standard patch management or Windows/Edge auto-update mechanisms. Given the volume of CVEs bundled into a single monthly-style release and the lack of reported in-the-wild exploitation, this should be treated as a routine but broad patch requirement rather than an emergency response.

## Mentioned in this report

- Vulnerabilities: CVE-2026-91708, CVE-2026-91709, CVE-2026-91710, CVE-2026-91711, CVE-2026-91712, CVE-2026-91713, CVE-2026-91714, CVE-2026-91715, CVE-2026-91716, CVE-2026-91717, CVE-2026-91718, CVE-2026-91719, CVE-2026-91720, CVE-2026-91721, CVE-2026-91722, CVE-2026-91723, CVE-2026-91724, CVE-2026-91725, CVE-2026-91726, CVE-2026-91727, CVE-2026-91728, CVE-2026-91729, CVE-2026-91730, CVE-2026-91731, CVE-2026-91733, CVE-2026-91734, CVE-2026-91735, CVE-2026-91736, CVE-2026-91737, CVE-2026-91738, CVE-2026-91739, CVE-2026-91740, CVE-2026-91741, CVE-2026-91742, CVE-2026-91743, CVE-2026-91744, CVE-2026-91745, CVE-2026-91746, CVE-2026-91747, CVE-2026-91748

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1208

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d2ec79f1-3fdf-523b-bf22-bcb9e6cce12b/cert-fr-flags-multiple-microsoft-edge-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
