Google Chrome zero-day added to CISA KEV — actively exploited, patch now
Monday brought an exploited Chrome flaw on CISA's KEV list, an emergency N-able N-central RCE hotfix, an Adobe Commerce zero-day backdooring stores, and breaches hitting Mathspace, Trezor and Berlin.
Start with the browser on every desktop. CISA's Known Exploited Vulnerabilities catalog lists CVE-2026-85046 as known to be exploited. The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base score 8.8. Google lists Chrome as affected up to the fix in 152.0.7977.82. Update to that build. CISA's entry directs stakeholders to apply mitigations per the vendor advisory and to follow BOD 26-04 patching guidance.
Google's Stable Channel update also fixes three further Chrome flaws, all affected up to the fix in 152.0.7977.75: CVE-2026-84325 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, 9.8), CVE-2026-84354 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, 9.6) and CVE-2026-84324 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H, 9.0). Mozilla's advisories cover two Firefox flaws scored 9.8 each: CVE-2026-84143 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), fixed in 140.15.0, and CVE-2026-84142 (same vector), fixed in 155.0.0.
Help Net Security reported that N-able released an emergency hotfix for a critical-CVSS-rated remote code execution flaw in N-central, its RMM product popular with managed service providers, and described it as exploited in the wild. MSPs should apply N-able's hotfix without delay, given the downstream blast radius across managed customers. SecurityWeek reported the StyleSmuggler zero-day lets attackers execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.
On worm-like activity: SecurityWeek and The Hacker News reported, citing Huntress, that modified ConnectWise ScreenConnect clients are being used to distribute a four-stage VBScript payload to newly connected hosts across three unrelated incidents. The Hacker News reported a TantoSec proof-of-concept turns a Telerik UI for ASP.NET AJAX padding-oracle into unauthenticated RCE, but only against a specific non-default configuration; Progress patched the chain in July.
Breaches: BleepingComputer reported Mathspace disclosed a breach affecting over 1 million students, staff and parents via its Metabase system, and that the Trezor/ShipMonk breach now reaches 81,000 customers. The Record reported Berlin is investigating a second government data leak, with Germany's information security agency warning about the Rhysida group. The Register reported hackers drained $320M in Bitcoin from Liquid Network. SecurityWeek reported a North Korean Linux espionage toolkit embedding a backdoor in HAProxy against South Korean automotive and media targets.
Sources
- The Register — Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys
- BleepingComputer — Mathspace discloses data breach affecting over 1 million people
- SecurityWeek — Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
- Help Net Security — N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
- The Record — Berlin investigates new data leak after hackers publish stolen login credentials
- The Hacker News — Your Cloud Security Checklist Doesn't Work the Way You Think It Does
- Schneier on Security — Automobile Camouflage to Hide from Flock Cameras
- BleepingComputer — Trezor data breach impact now reaches 81,000 customers
- SecurityWeek — North Korean Hackers Deploy New Linux Espionage Toolkit
- SecurityWeek — OpenAI Agents Hijack Another Victim Website
- SecurityWeek — Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- SecurityWeek — Modified ScreenConnect Clients Used in Worm-Like Campaign
- The Hacker News — Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
- The Hacker News — Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released