# Microsoft Edge zero-day exploited in the wild

Published: 2026-09-10 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/d6e8eaf0-5145-5706-ab28-495a9bfd4bff/microsoft-edge-zero-day-exploited-in-the-wild

> ANSSI warns CVE-2026-85046, a remote code execution flaw in Microsoft Edge versions before 152.0.4191.62, is being actively exploited.

ANSSI (CERT-FR) issued an advisory regarding CVE-2026-85046, a vulnerability affecting Microsoft Edge versions prior to 152.0.4191.62. The flaw allows an attacker to achieve remote arbitrary code execution. Microsoft has confirmed that this vulnerability is being actively exploited in the wild, making patching a priority for organizations running affected versions of the browser.

No technical details of the exploitation chain were disclosed in this bulletin. Defenders should apply the vendor patch referenced in the Microsoft Security Response Center bulletin as soon as possible, and prioritize deployment given the confirmed active exploitation status. Organizations should verify Edge browser versions across their fleet and ensure automatic updates are enabled or push the patch through managed update mechanisms.

## Mentioned in this report

- Vulnerabilities: CVE-2026-85046 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1159

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d6e8eaf0-5145-5706-ab28-495a9bfd4bff/microsoft-edge-zero-day-exploited-in-the-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
