Changeflow GovPing Data Privacy & Cybersecurity Microsoft Edge Vulnerability CVE-2026-3909
Urgent Notice Added Final

Microsoft Edge Vulnerability CVE-2026-3909

Favicon for www.cert.ssi.gouv.fr CERT-FR Security Advisories
Published March 17th, 2026
Detected March 17th, 2026
Email

Summary

CERT-FR has issued a security advisory regarding a vulnerability in Microsoft Edge, identified as CVE-2026-3909. The advisory notes that this vulnerability is actively being exploited and affects versions prior to 146.0.3856.62.

What changed

CERT-FR has released a security notice (CERTFR-2026-AVI-0303) detailing a vulnerability in Microsoft Edge, designated CVE-2026-3909. The advisory states that this vulnerability is actively exploited and affects Microsoft Edge versions prior to 146.0.3856.62. The specific risk is not detailed by the publisher, but the active exploitation indicates a significant security concern.

Affected organizations, particularly those using the specified versions of Microsoft Edge, are advised to consult the publisher's security bulletin for the necessary patches. Prompt application of updates is crucial to mitigate the risk of exploitation. While no specific penalties are mentioned, failure to patch actively exploited vulnerabilities can lead to severe security breaches, data loss, and operational disruption.

What to do next

  1. Update Microsoft Edge to version 146.0.3856.62 or later.
  2. Review security bulletin for CVE-2026-3909 for detailed mitigation steps.
  3. Implement enhanced monitoring for suspicious network activity related to Edge.

Source document (simplified)

Premier Ministre S.G.D.S.N

Agence nationale
de la sécurité des
systèmes d'information

Paris, le 17 mars 2026 N° CERTFR-2026-AVI-0303 Affaire suivie par: CERT-FR

Avis du CERT-FR

Objet: Vulnérabilité dans Microsoft Edge

Gestion du document

| Référence | CERTFR-2026-AVI-0303 |
| Titre | Vulnérabilité dans Microsoft Edge |
| Date de la première version | 17 mars 2026 |
| Date de la dernière version | 17 mars 2026 |
| Source(s) | Bulletin de sécurité Microsoft Edge CVE-2026-3909 du 16 mars 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.


Risque

  • Non spécifié par l'éditeur

Systèmes affectés

  • Microsoft Edge versions antérieures à 146.0.3856.62

Résumé

Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Microsoft indique que la vulnérabilité CVE-2026-3909 est activement exploitée.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation


Gestion détaillée du document

  1. le 17 mars 2026 Version initiale

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-FR
Published
March 17th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Manufacturers Technology companies
Geographic scope
National (France)

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software Vulnerabilities Patch Management

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-FR Security Advisories publishes new changes.

Free. Unsubscribe anytime.