Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Chromium CVE-2026-87491: Out of bounds write in V8

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases. googleblog. com/20)2)6) for more information. Google is aware that an exploit for CVE-2026-87491 exists in the wild.

·Microsoft Security Update Guide
Read →
Vulnerabilities & Patches
Emerging1 src

U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2025-25249  Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability • CVE-2026-19490  Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability • CVE-2026-87491  Google Chromium V8 Out of Bounds Write Vulnerability • CVE-2026-20079  Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-20079 (CVSS score of 10. 0) is an authentication bypass issue.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

Google fixes the seventh actively exploited Chrome zero-day of 2026

Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8. 8). The medium-severity flaw affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine. An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome’s sandbox. Google fixed the issue in Chrome 153. 0. 8010. 36 and later versions. “CVE-2026-87491: Out of bounds write in V8” reads the advisory . “Google is aware that an exploit for CVE-2026-87491 exists in the wild.”

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Google fixes second actively exploited Chrome zero-day in under five days

Google has released Chrome 153 to the stable channel with fixes for 230 security vulnerabilities, including a V8 memory corruption flaw that Google says is already being exploited in attacks. The actively exploited vulnerability is tracked as CVE-2026-87491 and is described as an out-of-bounds write in V8, Chrome’s JavaScript and WebAssembly engine. It was reported … The post Google fixes second actively exploited Chrome zero-day in under five days appeared first on CyberInsider .

·CyberInsider
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-87491 Detail - National Institute of Standards and Technology (.gov)

CVE-2026-87491 Detail National Institute of Standards and Technology (.gov)

·NVD
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-87491 - Google Chromium V8 Out of Bounds Write Vulnerability

Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

·CISA KEV
Read →

You've reached the end of current stories for this search.