Chisato · · 6 min read Chrome Zero-Day CVE-2026-85046: V8 Flaw Exploited
Google patched CVE-2026-85046, an actively exploited V8 type-confusion zero-day in Chrome and the sixth of 2026. Affected versions, the risk, and how to patch.
Topic
6 posts tagged “Zero-Day”.
Chisato · · 6 min read Google patched CVE-2026-85046, an actively exploited V8 type-confusion zero-day in Chrome and the sixth of 2026. Affected versions, the risk, and how to patch.
Chisato · · 5 min read PaperCut is patching two zero-days in NG and MF — a pre-auth RCE and an access-control flaw — exploited in the wild. All versions affected. Apply Release 2.
Chisato · · 7 min read North Korea's Lazarus group exploited a Windows AFD.sys zero-day (CVE-2026-68820) for five weeks to breach defense firms and deploy the FudModule rootkit.
Chisato · · 5 min read An unpatched GeoServer SQL injection zero-day rated CVSS 9.8 is under active exploitation. The flaw, affected versions, the fix, and what to do now.
Chisato · · 4 min read A critical CVSS 9.8 directory-traversal flaw in VMware vCenter is under active attack across 47 countries. Affected versions, the exploit chain, and the fix.
Chisato · · 6 min read A CVSS 10.0 SQL injection zero-day in Metabase was exploited in the wild to steal database credentials. Affected versions, the fix, and what it means.