Microsoft Edge zero-day exploited in the wild
ANSSI warns CVE-2026-85046, a remote code execution flaw in Microsoft Edge versions before 152.0.4191.62, is being actively exploited.
ANSSI (CERT-FR) issued an advisory regarding CVE-2026-85046, a vulnerability affecting Microsoft Edge versions prior to 152.0.4191.62. The flaw allows an attacker to achieve remote arbitrary code execution. Microsoft has confirmed that this vulnerability is being actively exploited in the wild, making patching a priority for organizations running affected versions of the browser.
No technical details of the exploitation chain were disclosed in this bulletin. Defenders should apply the vendor patch referenced in the Microsoft Security Response Center bulletin as soon as possible, and prioritize deployment given the confirmed active exploitation status. Organizations should verify Edge browser versions across their fleet and ensure automatic updates are enabled or push the patch through managed update mechanisms.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1159
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free