Three actively exploited flaws hit CISA's KEV list — Chrome and Windows Server both named
CISA lists one Google Chrome flaw and two Microsoft Windows Server flaws as known to be exploited, while SecurityWeek reports a new zero-day exploit that provides full System privileges on Windows machines running the September 2026 patches and targets Microsoft Defender.
Start with the three flaws CISA lists as known to be exploited. CVE-2026-87491 affects Google Chrome up to the fix in 153.0.8010.36; its CVSS:3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base score 8.8, requiring user interaction over the network. CVE-2026-85880 and CVE-2026-81963 both affect Microsoft Windows Server, each carrying the CVSS:3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, base score 7.8 — local, low-privilege paths to full confidentiality, integrity and availability loss. Match your estate against those products and treat them as first in the queue.
For remediation, Google's advisory names the fixed Chrome release as 153.0.8010.36. Microsoft's advisory names the fixed Windows Server builds as 10.0.14393.9512 for CVE-2026-85880 and 10.0.26100.33438 for CVE-2026-81963. Apply the vendor patches named in each advisory. CISA directs stakeholders to evaluate each asset's internet exposure and follow BOD 26-04 patching guidance.
Google's same Chrome release also fixes three flaws that are not on the KEV list: CVE-2026-87654, CVE-2026-87650 and CVE-2026-87646. Each carries the CVSS:3.1 vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, a scope change with a base score of 9.6. Updating Chrome to 153.0.8010.36 addresses these alongside the exploited one.
SecurityWeek reports a new zero-day exploit it calls "ShieldCrash" targeting Microsoft Defender, and says the exploit provides full System privileges on Windows machines running the September 2026 patches.
In other reporting for the day: BleepingComputer reports that Microsoft's September 2026 Patch Tuesday updates fix a known issue that caused desktop settings to be lost or reset on some Windows devices. SecurityWeek reports a Fortinet unauthenticated code execution flaw, patched in January 2026, is being exploited in PivotC2 RAT attacks. BleepingComputer reports that Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. Help Net Security, citing Barracuda researchers, reports a phishing campaign that routes victims through genuine Microsoft OAuth and Teams infrastructure before assembling a fake login page entirely inside the victim's own browser. The Hacker News reports the U.S. Department of Justice announced actions against the Xinbi Guarantee scam marketplace, seizing Telegram channels, confiscating two cryptocurrency wallets and freezing $52.8 million in crypto.
Sources
- BleepingComputer — Microsoft fixes bug that wiped Windows desktop settings
- SecurityWeek — New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
- The Register — Dental contractor set up secret account with access to 4,000 patient records then left the company
- Help Net Security — Product showcase: GitGuardian Honeytoken catches credential theft as it happens
- The Record — CISA head says agency must change quickly to prevent the 'worst that could happen'
- The Hacker News — U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
- BleepingComputer — Trezor warns users of email provider breach, phishing attacks
- SecurityWeek — Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
- Help Net Security — Cybercriminals are building phishing pages that exist only inside victims’ browsers
- Help Net Security — AI adoption brings new security headaches for already stretched CISOs
- Help Net Security — A new open standard locks AI weights to approved hardware
- Help Net Security — Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity
- The Register — Anthropic reveals fourth likely crime committed by its AI
- The Register — Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits