Google patches sixth Chrome zero-day of 2026 (CVE-2026-85046). A type confusion flaw in Chrome's V8 JavaScript engine is actively exploited in the wild and has been added to CISA's KEV catalog. FCEB agencies have a mandatory remediation deadline; all organizations should treat this as priority-one patching. Learn more
Unpatched Magento and Adobe Commerce zero-day StyleSmuggler exploited to backdoor stores. A zero-day vulnerability affecting all current versions of Magento Open Source and Adobe Commerce allows unauthenticated remote code execution and persistent backdoor installation. Attacks began before public disclosure, and no patch is currently available, making workarounds and WAF rules the only near-term mitigation.
Critical Citrix NetScaler auth bypass (CVE-2026-19490) now under active attack. Attackers are exploiting the authentication bypass in Citrix NetScaler appliances, with exploitation attempts confirmed from multiple countries. National cybersecurity agencies are urging immediate patching; any internet-facing NetScaler should be treated as potentially compromised until updated.
SonicWall SMA 1000 hit by two chained zero-days enabling unauthenticated RCE. CVE-2026-83548 (SSRF) and CVE-2026-83549 (OS command injection) can be chained to achieve remote code execution without authentication on SMA 1000 appliances. SonicWall's track record as a high-value target for ransomware and nation-state actors makes urgent patching critical for any organization running this product.
Key Takeaway
Patch Chrome immediately, implement WAF rules for Magento installs, and treat unpatched Citrix NetScaler and SonicWall SMA 1000 appliances as incident-response priorities this week.
