The Canadian Centre for Cyber Security issued advisory AV26-143 urging organizations to update Microsoft Edge Stable to remediate vulnerabilities affecting versions prior to 145.0.3800.58. Microsoft indicated that CVE-2026-2441 has an available exploit, increasing the likelihood of active or imminent abuse, and the advisory directs administrators to apply Microsoft’s February 2026 Edge security update.
In parallel, Microsoft began rolling out Edge 145 to the Stable channel with multiple enterprise security enhancements, including expanded data protection for Edge for Business (cross-tenant Intune App Protection Policies, DLP controls such as clipboard limits, watermarks, protected downloads, and leak controls for screenshots and developer tools). The release also adds stronger extension governance (detection/revocation of malicious sideloaded extensions and extension monitoring via the Edge management service) and improvements to password handling via a password affiliation service for related domains—changes that complement the security posture improvements delivered alongside the security fixes in the Edge 145 line.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-143 warning that Microsoft had released an Edge security update and urging users and administrators to review Microsoft's release notes and apply the update. The notice highlighted that the update fixed vulnerabilities affecting versions before 145.0.3800.58.
Microsoft rolled out Edge 145 to the Stable channel in a phased deployment, adding enterprise-focused protections such as expanded Edge for Business data protection, watermarking, protected clipboard controls, OneDrive for Business download redirection, and stronger extension security monitoring. The release also introduced administrative controls for profile editing, web app installation, and oversight of AI-generated application execution via Safe Hosting extension policy.
Microsoft published a security update for the Microsoft Edge Stable Channel on February 14, 2026, addressing vulnerabilities in versions prior to 145.0.3800.58. Microsoft indicated that an exploit was available for CVE-2026-2441.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.