1. Top Action Item
Update Google Chrome to version 152.0.7977.82 or later immediately. Google is reporting active in-the-wild exploitation of CVE-2026-85046, a high-severity type-confusion vulnerability in Chrome's V8 JavaScript engine (CVSS 8.8) that affects Chrome users broadly on Windows, macOS, and Linux. Restart the browser after the update to apply it, and if you manage Chrome at scale, treat this as an emergency deployment rather than a routine patch-cycle item.
2. Exploited This Week
Google Chrome — CVE-2026-85046 (V8 type confusion)
- Source: The Hacker News
- Link: The Hacker News
- Severity: High (CVSS 8.8)
- What's happening: Google's Thursday security update fixes 12 vulnerabilities, including CVE-2026-85046, which is confirmed to be actively exploited in the wild; it affects Chrome prior to 152.0.7977.82.
- Fix: Apply Chrome 152.0.7977.82 or later (automatic update plus browser restart).
Magento Open Source / Adobe Commerce — "StyleSmuggler" (no CVE disclosed)
- Source: The Hacker News / Sansec
- Link: The Hacker News
- Severity: See source — unauthenticated code execution on the store's server
- What's happening: Sansec reports attackers have been exploiting an unpatched vulnerability since September 4 to run malicious code and backdoor online stores without logging in; a patch is not yet available.
- Fix: No patch at time of writing — watch Sansec and Adobe/Magento for an update, and inspect storefronts for signs of backdooring or unauthorized code.
PaperCut — CVE-2026-81578 / CVE-2026-82078 (authentication bypass + RCE chain)
- Source: The Hacker News / Arctic Wolf
- Link: The Hacker News
- Severity: See source (auth-bypass to remote-code-execution chain)
- What's happening: Arctic Wolf observed threat actors exploiting the two newly disclosed flaws — an authentication bypass and an RCE — against schools and universities in the U.S. and Europe to run commands, perform reconnaissance, and steal credentials.
- Fix: Apply the latest PaperCut security update (patched version numbers in the vendor advisory).
SonicWall SMA 1000 — zero-days (CVE(s) not stated in report)
- Source: Dark Reading
- Link: Dark Reading
- Severity: See source — unauthenticated remote code execution
- What's happening: Exploitation activity is underway against SonicWall SMA 1000 zero-day vulnerabilities, following attacks earlier this summer against two other zero-days in SonicWall edge devices.
- Fix: Apply the SonicWall SMA 1000 firmware update referenced in the article/vendor advisory.
WordPress: Super Forms (CVE-2026-14894) & Elementor Pro
- Source: The Hacker News / Wordfence
- Link: The Hacker News
- Severity: Super Forms CVE-2026-14894 is Critical (CVSS 9.8); Elementor Pro severity see source
- What's happening: Wordfence reports 440,000+ exploit attempts against two WordPress plugins — a missing file-type-validation flaw in Super Forms allowing unauthenticated file uploads of any type, and an RCE flaw in Elementor Pro.
- Fix: Update Super Forms and Elementor Pro to the patched versions referenced by Wordfence.
JetBrains TeamCity / Cadence — CVE not stated in report
- Source: The Hacker News
- Link: The Hacker News
- Severity: See source (critical TeamCity vulnerability referenced as recently disclosed)
- What's happening: JetBrains disclosed that unidentified attackers exploited an unpatched critical TeamCity vulnerability to breach JetBrains' own environment and accessed credentials associated with its Cadence service.
- Fix: JetBrains urges Cadence users to immediately revoke or rotate all credentials/secrets used for Cadence executions; TeamCity users should apply the vendor's security update (see source).
3. Critical Patch Roundup
VMware Workstation & Fusion — CVE-2026-59346
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (CVSS 9.3)
- What's happening: An integer-overflow vulnerability can, under certain conditions, let a local attacker with elevated privileges execute arbitrary code on the host. Broadcom has released security updates for Workstation and Fusion.
- Fix: Install the Broadcom-updated VMware Workstation/Fusion builds referenced in the advisory.
PostgreSQL — CVE-2026-6471
- Source: The Hacker News
- Link: The Hacker News
- Severity: High (CVSS 7.2)
- What's happening: A flaw present since logical decoding shipped in PostgreSQL 9.4 (2014) lets an account with the REPLICATION attribute execute arbitrary code as the OS user running the database server.
- Fix: Upgrade to PostgreSQL 18.6, 17.11, 16.15, 15.19, or 14.24; versions before those are vulnerable.
4. Home / SOHO Impact
- Update Chrome now to version 152.0.7977.82 or later — the V8 flaw (CVE-2026-85046) is actively exploited. After updating, fully quit and reopen Chrome.
- Plex users: install Plex Media Server 1.43.3 and Plex Desktop 1.115.0; Plex is urging immediate updates after patching multiple undisclosed security flaws.
- If you run a small online store on Magento or Adobe Commerce: there is no patch yet for the actively exploited "StyleSmuggler" issue — monitor vendor/Sansec advisories and have your host or developer check the store for tampering or backdoors.
- WordPress site owners: update the Super Forms and Elementor Pro plugins now; over 440,000 exploit attempts have already been recorded against them.
- If you run VMware Workstation or Fusion on a home machine, apply Broadcom's update for CVE-2026-59346 (critical, CVSS 9.3) rather than deferring it.
- Watch for tricky phishing: Microsoft warns of a high-volume campaign using invisible Unicode characters to smuggle financial lure words like "funding" past email filters — be suspicious of unexpected payment/funding emails even if they look clean.
5. Enterprise Impact
- Patch PaperCut immediately, especially in education: Arctic Wolf observed CVE-2026-81578 + CVE-2026-82078 being chained in credential-theft attacks against schools and universities in the U.S. and Europe. Prioritize any exposed or internet-facing PaperCut servers.
- Treat SonicWall SMA 1000 as an emergency: the exploited zero-days allow unauthenticated RCE on remote-access gear, and this vendor has already been hit twice this summer on other edge-device zero-days. Apply the firmware update and review access logs for post-exploitation activity.
- If you use JetBrains TeamCity or Cadence in your build pipeline: rotate and revoke all credentials and secrets that may have run Cadence executions, and apply the referenced TeamCity security update — the incident shows attackers are willing to use unpatched TeamCity against the vendor itself.
- E-commerce / hosting providers: Magento Open Source and Adobe Commerce stores are being backdoored via the unpatched StyleSmuggler flaw with no fix yet. Add detection monitoring for unauthorized code and changes on storefront servers, and quarantine compromised stores.
- Harden WordPress fleets: the Super Forms (CVE-2026-14894, CVSS 9.8) and Elementor Pro RCE flaws are under mass exploitation; push the plugin updates centrally and consider WAF rules for the attack patterns Wordfence documented.
- Update PostgreSQL databases to the fixed 18.6 / 17.11 / 16.15 / 15.19 / 14.24 line — the 12-year-old logical-decoding flaw (CVE-2026-6471) gives REPLICATION-role accounts code execution as the database OS user.
- Remind staff about voice-phishing and financial fraud campaigns: the "Spring Ring" operation abuses Microsoft Teams vishing to gain remote session access and deploy malware, and the "Phantom Deal" M&A campaign targets midlevel employees to initiate large transfers — verify such requests out-of-band.
6. What To Patch First
- Google Chrome 152.0.7977.82+ — CVE-2026-85046 (actively exploited zero-day)
- PaperCut (latest build) — CVE-2026-81578 / CVE-2026-82078 (exploited in education-sector attacks)
- SonicWall SMA 1000 (latest firmware) — zero-day unauthenticated RCE (exploited; CVEs see source)
- VMware Workstation & Fusion (Broadcom update) — CVE-2026-59346 (critical, CVSS 9.3)
- WordPress Super Forms & Elementor Pro (latest versions) — CVE-2026-14894 plus Elementor RCE (critical / mass exploitation attempts)
- PostgreSQL 18.6 / 17.11 / 16.15 / 15.19 / 14.24 — CVE-2026-6471 (high severity, 12-year-old flaw)
- JetBrains TeamCity / Cadence — apply TeamCity update and rotate Cadence credentials (see source; exploited against JetBrains)
- Plex Media Server 1.43.3 / Plex Desktop 1.115.0 — multiple undisclosed security fixes (vendor urges immediate update)
- Magento / Adobe Commerce — no patch yet; monitor for vendor update and scan for backdoors (actively exploited zero-day)
Sources
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores — https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials — https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code — https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities — https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html
- Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters — https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html
- PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution — https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html
- Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws — https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html
- Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws — https://thehackernews.com/2026/09/plex-urges-immediate-updates-after.html
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day — https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html
- SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE — https://www.darkreading.com/vulnerabilities-threats/sonicwall-sma-1000-zero-days-unauthenticated-rce
- Large Enterprises Targeted in Fake Merger & Acquisition Scams — https://www.darkreading.com/cyberattacks-data-breaches/large-enterprises-fake-merger-acquisition-scams
- Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams — https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/