Microsoft patches 252 Edge vulnerabilities
Microsoft released Edge 149.0.4022.52 addressing 252 CVEs with unspecified security impact; CERT-FR advises immediate patching.
France's CERT-FR has issued an advisory for multiple vulnerabilities discovered in Microsoft Edge browser versions prior to 149.0.4022.52. The advisory references 252 distinct CVE identifiers ranging from CVE-2026-10881 through CVE-2026-11132, all dated June 5, 2026. Microsoft has characterized these vulnerabilities as causing unspecified security issues, declining to provide detailed descriptions of the flaws or their potential impact.
The sheer volume of vulnerabilities patched in a single release is unusual, suggesting either a major security audit of the Edge codebase or accumulated fixes from the underlying Chromium project. Given Edge's Chromium foundation, many of these CVEs likely originate from the open-source browser engine and affect multiple browser vendors. The lack of specificity from Microsoft regarding severity or exploitability makes it difficult to assess immediate risk, though the French national CERT's publication indicates concern warranting administrator attention.
Organizations running Microsoft Edge should prioritize deployment of version 149.0.4022.52 or later. The advisory provides no indicators of active exploitation, but the vendor's decision to withhold vulnerability details may indicate sensitivity around certain flaws. System administrators should consult Microsoft's Security Response Center for patch deployment guidance and monitor for any subsequent disclosures regarding specific CVE criticality.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0700
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free