1. Top Action Item

Update Google Chrome to version 152.0.7977.82 or later immediately. Google is reporting active in-the-wild exploitation of CVE-2026-85046, a high-severity type-confusion vulnerability in Chrome's V8 JavaScript engine (CVSS 8.8) that affects Chrome users broadly on Windows, macOS, and Linux. Restart the browser after the update to apply it, and if you manage Chrome at scale, treat this as an emergency deployment rather than a routine patch-cycle item.


2. Exploited This Week

Google Chrome — CVE-2026-85046 (V8 type confusion)

Magento Open Source / Adobe Commerce — "StyleSmuggler" (no CVE disclosed)

PaperCut — CVE-2026-81578 / CVE-2026-82078 (authentication bypass + RCE chain)

SonicWall SMA 1000 — zero-days (CVE(s) not stated in report)

WordPress: Super Forms (CVE-2026-14894) & Elementor Pro

JetBrains TeamCity / Cadence — CVE not stated in report


3. Critical Patch Roundup

VMware Workstation & Fusion — CVE-2026-59346

PostgreSQL — CVE-2026-6471


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. Google Chrome 152.0.7977.82+ — CVE-2026-85046 (actively exploited zero-day)
  2. PaperCut (latest build) — CVE-2026-81578 / CVE-2026-82078 (exploited in education-sector attacks)
  3. SonicWall SMA 1000 (latest firmware) — zero-day unauthenticated RCE (exploited; CVEs see source)
  4. VMware Workstation & Fusion (Broadcom update) — CVE-2026-59346 (critical, CVSS 9.3)
  5. WordPress Super Forms & Elementor Pro (latest versions) — CVE-2026-14894 plus Elementor RCE (critical / mass exploitation attempts)
  6. PostgreSQL 18.6 / 17.11 / 16.15 / 15.19 / 14.24 — CVE-2026-6471 (high severity, 12-year-old flaw)
  7. JetBrains TeamCity / Cadence — apply TeamCity update and rotate Cadence credentials (see source; exploited against JetBrains)
  8. Plex Media Server 1.43.3 / Plex Desktop 1.115.0 — multiple undisclosed security fixes (vendor urges immediate update)
  9. Magento / Adobe Commerce — no patch yet; monitor for vendor update and scan for backdoors (actively exploited zero-day)

Sources