Chrome Zero-Day CVE-2026-2441 Exploited in the Wild
Google patches CVE-2026-2441, a high-severity use-after-free in Chrome actively exploited in the wild. This is Chrome first zero-day of 2026. Update immediately.
Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.
Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.
Updated September 11, 2026 — all 201 published advisories are browsable here. The newest one is on the appliance that is supposed to be doing the protecting: a Cisco firewall management flaw under active attack and added to CISA's known-exploited list, on the console that controls the firewalls guarding the whole network (CVE-2026-20079). Behind it, a Chrome zero-day exploited in the wild, where simply visiting a booby-trapped site is enough to get code running on the machine (CVE-2026-87491), and a FreeIPA flaw that hands full administrator rights to anyone who connects without a password, on the directory server that decides who gets into everything else (CVE-2026-76578). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.
Google patches CVE-2026-2441, a high-severity use-after-free in Chrome actively exploited in the wild. This is Chrome first zero-day of 2026. Update immediately.
A critical pre-authentication RCE vulnerability in BeyondTrust Remote Support and Privileged Remote Access is now being actively exploited after a proof-of-concept was published. With a CVSS of 9.9 and approximately 8,500 unpatched on-premise deployments exposed, organizations must patch immediately.
Read moreMultiple coordinated campaigns have compromised millions of Chrome users through fake AI assistants, social media tools, and utility extensions. The AiFrame campaign alone infected 300,000 users with fake ChatGPT and Gemini extensions that steal emails and credentials, while 287 extensions with 37 million installs were found exfiltrating browsing history to data brokers.
Read moreSecurity researchers at Koi Security discovered the first known malicious Microsoft Outlook add-in, dubbed AgreeToSteal. Attackers hijacked an abandoned legitimate calendar tool by claiming its orphaned Vercel URL, turning Microsoft's own infrastructure into a phishing delivery mechanism that harvested over 4,000 Microsoft account credentials.
Read moreApple patches CVE-2026-20700, a memory corruption flaw in dyld exploited in sophisticated attacks. The vulnerability completes a three-stage exploit chain with two December 2025 bugs (CVE-2025-14174, CVE-2025-43529) discovered by Google TAG, likely used in mercenary spyware operations.
Read moreMicrosoft's February 2026 Patch Tuesday fixes 59 vulnerabilities including six actively exploited zero-days. CISA has added all six to KEV with March 3rd deadline. Critical bugs in Windows Shell, MSHTML, Word, and privilege escalation in Desktop Window Manager and Remote Desktop.
Read moreSmarterTools confirms the Warlock ransomware gang breached their network through a forgotten, unpatched SmarterMail server. The attackers exploited known vulnerabilities (CVE-2026-23760, CVE-2026-24423) to gain access, then moved laterally before deploying ransomware.
Read moreTGR-STA-1030, a state-backed Asian threat group, breached 70+ government and critical infrastructure organizations across 37 countries since January 2024. They exfiltrated financial negotiations, military updates, and banking info using Cobalt Strike, web shells, and eBPF rootkits.
Read moreCritical vulnerabilities in Kubernetes Ingress-NGINX (CVE-2025-1974 and related) allow unauthenticated attackers with pod network access to achieve RCE via file descriptor injection. Default installations expose all cluster Secrets. Public exploit available.
Read moreCloudflare mitigated a record-breaking 31.4 Tbps DDoS attack from the AISURU/Kimwolf botnet, powered by 2 million compromised Android devices. DDoS attacks surged 121% in 2025 with 47.1 million incidents. The botnet spread via trojanized Android apps and fake Windows binaries.
Read moreCVE-2026-25049 (CVSS 9.4) bypasses the fix for CVE-2025-68613 using JavaScript destructuring tricks. Authenticated users can escape n8n expression sandbox and achieve RCE via webhook-triggered workflows. Four additional CVEs disclosed alongside.
Read moreCVE-2025-25257 is a pre-authentication SQL injection in FortiWeb Fabric Connector that enables remote code execution. Actively exploited in the wild with public PoC available. Affects FortiWeb 7.0.x through 7.6.x. CISA KEV listed.
Read moreResearchers discovered DockerDash, a critical vulnerability in Docker Ask Gordon AI feature that lets attackers execute code by hiding malicious instructions in image metadata. The attack exploits blind trust between the AI assistant and MCP Gateway. Patched in Docker Desktop 4.50.0.
Read moreEmail-stealing malware has become a cornerstone of modern espionage and cybercrime. Here's how these tools work, why attackers love them, and what you can do about it.
Read moreRussia's APT28 began exploiting Microsoft Office CVE-2026-21509 just 72 hours after disclosure, targeting Ukraine, Slovakia, and Romania with email-stealing malware and Covenant implants.
Read moreMicrosoft announces three-phase plan to disable NTLM by default in Windows, pushing enterprises toward Kerberos authentication after decades of security issues.
Read moreA Chinese state-sponsored group turned Anthropic's Claude into the hacker itself, building a framework that allowed the AI to independently infiltrate networks, harvest credentials, and steal data. This was the first documented case of AI doing the hacking, not just assisting it.
Read moreThis week's cybersecurity developments demonstrate how quickly attackers are co-opting existing infrastructure. From Google's disruption of the IPIDEA residential proxy network to Microsoft's 114-flaw Patch Tuesday, the patterns show attackers prioritizing persistence over speed.
Read moreA critical authentication bypass vulnerability (CVSS 9.8) in Fortinet FortiOS, FortiManager, FortiAnalyzer, FortiProxy, and FortiWeb allows attackers with a FortiCloud account to access devices registered to other accounts when FortiCloud SSO is enabled. This vulnerability is actively being exploited in the wild.
Read moreA high-severity Microsoft Office zero-day (CVE-2026-21509) is being actively exploited to bypass security controls designed to block risky COM and OLE content. Successful exploitation requires a user to open a malicious Office document, enabling follow-on payload execution and intrusion activity. Apply Microsoft's out-of-band update immediately or deploy the recommended registry-based mitigation if patching is delayed.
Read moreOur CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.
Subscribe to our newsletter and get the latest security insights delivered to your inbox.