Multiples vulnérabilités dans Microsoft Edge (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
CSIRTS triage
- What
- Multiple unspecified security vulnerabilities exist in Microsoft Edge that allow attackers to cause unspecified security issues.
- Who is affected
- Users of Microsoft Edge on all platforms are affected.
- Urgency
- Moderate urgency; multiple CVEs are assigned but specific details and exploitation status are not provided.
- Action
- Update Microsoft Edge to the latest available version that addresses CVE-2026-84357, CVE-2026-84347, CVE-2026-84349, CVE-2026-84354, CVE-2026-84329, CVE-2026-84325, CVE-2026-84348, and CVE-2026-84324.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Edge
Get an email when a new Edge advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1116/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-843570.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-843470.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-843490.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-843540.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-843290.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-843250.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-843480.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-843240.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-843280.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-843340.08% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highPAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) (Severity: HIGH)paloalto
- high[UPDATE] [hoch] Google Chrome: Mehrere Schwachstellencert-bund
- unknownCVE-2026-84350: Chromium: CVE-2026-84350 Use after free in TabStripmsrc
- unknownCVE-2026-84325: Chromium: CVE-2026-84325 Improper input validation in DataTransfermsrc
- unknownCVE-2026-84332: Chromium: CVE-2026-84332 Incorrect authorization in SiteSettingsmsrc
- unknownCVE-2026-84334: Chromium: CVE-2026-84334 Incorrect authorization in Chromotingmsrc
- unknownCVE-2026-84326: Chromium: CVE-2026-84326 Uninitialized resource in V8msrc
- unknownCVE-2026-84355: Chromium: CVE-2026-84355 Incorrect authorization in Navigationmsrc
- unknownCVE-2026-84348: Chromium: CVE-2026-84348 Information leak in MediaCapturemsrc
- unknownCVE-2026-84328: Chromium: CVE-2026-84328 Missing authorization in FileSystemmsrc
- unknownCVE-2026-84323: Chromium: CVE-2026-84323 Missing authorization in FileSystemmsrc
- unknownCVE-2026-84351: Chromium: CVE-2026-84351 Buffer overflow in GPUmsrc
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Microsoft Office (09 septembre 2026)2026-09-09
- unknownMultiples vulnérabilités dans les produits Microsoft (09 septembre 2026)2026-09-09
- unknownMultiples vulnérabilités dans Microsoft Azure (09 septembre 2026)2026-09-09
- unknownMultiples vulnérabilités dans Google Chrome (09 septembre 2026)2026-09-09
- unknownVulnérabilité dans les produits ESET (09 septembre 2026)2026-09-09