Two Chrome Zero-Days Exploited Now — Patch Immediately
Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. September 12, 2026
cybr.cx — Daily Digest | September 12, 2026
Critical Vulnerabilities
⚠️ Actively exploited — CVE-2026-87491 & CVE-2026-85046 | Google Chromium V8
Two V8 engine vulnerabilities are being actively exploited in the wild right now. CVE-2026-87491 is an out-of-bounds write enabling arbitrary code execution inside the sandbox via a crafted HTML page; CVE-2026-85046 is a type confusion bug with the same impact. Both affect Chrome, Edge, and any Chromium-derived browser. If you haven't pushed browser updates across your estate this week, stop reading and do that first.
⚠️ Actively exploited — CVE-2026-19490 | Citrix NetScaler ADC & Gateway
An authentication-bypass via an alternate path allows unauthenticated remote attackers to bypass AAA and Gateway configurations — SSL VPN, ICA Proxy, CVPN, and RDP Proxy are all affected. CISA's patch deadline was today. If your appliances aren't patched, assume exposure and begin hunting now.
⚠️ Actively exploited — CVE-2026-20079 | Cisco Secure Firewall Management Center & Security Cloud Control
Unauthenticated remote attackers can bypass authentication entirely and execute script files on Cisco FMC and SCC. CISA deadline was also today. This is your firewall management plane — treat it as a critical breach risk.
⚠️ Actively exploited — CVE-2026-84869 | ConnectWise ScreenConnect
Improper privilege management and missing authorisation allow attackers to perform file transfers and execute files through active remote sessions without authorisation or host confirmation. CISA's patch deadline is September 14 — two days away. RMM tools remain high-value targets for ransomware operators; this one is being actively abused.
⚠️ Actively exploited — CVE-2026-85706 | GitLab CE/EE
An unauthenticated path traversal in the repository commits API allows arbitrary file reads from the server. No authentication required. If you're running a self-hosted GitLab instance, patch before September 14 or take it off the public internet immediately.
⚠️ Actively exploited — CVE-2026-42016 & CVE-2026-42018 | JFrog Artifactory
Two concurrent Artifactory vulnerabilities are being exploited together. CVE-2026-42016 is an incorrect authorisation flaw that enables privilege escalation by validating token signatures without checking scope. CVE-2026-42018 can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Combined, these represent a significant supply chain risk — Artifactory sits at the heart of many build pipelines.
⚠️ Actively exploited — CVE-2026-86060 & CVE-2026-67277 | MikroTik RouterOS
Both CISA deadlines fall tomorrow, September 13. CVE-2026-86060 allows argument delimiter injection to manipulate RouterOS policy masks for privilege escalation. CVE-2026-67277 is a missing authentication flaw in the btest service that exposes kernel memory and enables denial of service. MikroTik devices are embedded across ISPs and enterprise networks globally — patch or isolate.
⚠️ Actively exploited — CVE-2025-25249 | Fortinet FortiOS, FortiSwitchManager, FortiSASE
A heap-based buffer overflow triggered by specially crafted packets allows unauthenticated code execution. CISA deadline was September 12. Fortinet edge devices are a perennial target for nation-state actors — verify your patch status now.
⚠️ Actively exploited — CVE-2026-81963 & CVE-2026-85880 | Microsoft Windows
CVE-2026-81963 is a link-following vulnerability in the Windows Update Stack that allows local privilege escalation to SYSTEM. CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) with the same outcome. Both are classic post-exploitation escalation primitives; patch these via your standard Windows update cycle if you haven't already.
⚠️ Actively exploited — CVE-2026-86218 | N-able N-central
A static code injection vulnerability in N-able's RMM platform enables pre-authentication remote code execution. CISA deadline was September 11 — yesterday. Like ScreenConnect, RMM compromise is a ransomware operator's preferred entry point for mass-deployment of payloads.
⚠️ Actively exploited — CVE-2026-75650 | Adobe Commerce & Magento Open Source
Template engine injection allows arbitrary code execution. CISA deadline was also September 11. Magento remains one of the most targeted e-commerce platforms; skimmer operators in particular will move quickly on this.
New this cycle — IBM Langflow OSS (CVE-2026-78569, CVE-2026-79742, CVE-2026-81940, CVE-2026-84889) | CVSS 8.8
Four distinct remote code execution paths have been disclosed across IBM Langflow OSS versions 1.0.0–1.11.5 (one limited to 1.10.3). The flaws span an incomplete security scanner denylist, an incomplete environment variable blocklist, special character injection via flow display names, and a path traversal vulnerability. Langflow's visual AI pipeline builder is increasingly deployed in enterprise AI workflows — four RCE bugs in a single release cycle is a serious concern.
New this cycle — IBM DataStage on Cloud Pak for Data (CVE-2026-82097, CVE-2026-82099, CVE-2026-81551) | CVSS 8.8
DataStage brings three new high-severity vulnerabilities: an SSRF enabling arbitrary code execution, an OS command injection flaw, and a path traversal that allows arbitrary file writes and deletions on shared storage. All affect version 5.4.0.0. DataStage runs data integration pipelines in regulated industries — command injection on shared storage in those environments is particularly damaging.
New this cycle — CVE-2026-75624 | IBM App Connect Enterprise | CVSS 8.8
An incorrect authorisation flaw in IBM ACE versions 12 and 13 allows remote authenticated attackers to bypass security restrictions. ACE sits in integration middleware stacks handling sensitive inter-system data flows; privilege abuse here can pivot broadly.
Headline News
OpenAI's products implicated in a major cyberattack — then Altman pitches AI as the cure
A striking conflict of interest has emerged following reports that OpenAI's products played a role in a sprawling cyberattack against critical infrastructure. Sam Altman subsequently held meetings with senior executives at major US power utilities, proposing OpenAI's cyber services as a solution to grid security challenges — the same week those revelations were still unfolding. For security practitioners, this raises serious questions about the accountability and vetting processes governing AI vendors that are simultaneously seeking deep access to critical national infrastructure. The power sector's operational technology environments are notoriously difficult to defend, and any AI integration into that control plane dramatically expands the attack surface. This story is worth tracking: the intersection of AI vendor liability, critical infrastructure protection, and the regulatory vacuum around AI-powered security tooling is becoming one of the defining tensions in the field.
Anthropic disrupts Russian and Chinese influence operations abusing Claude
Anthropic has disclosed the disruption of multiple state-linked campaigns that systematically abused its Claude large language model over an eight-month period, attributing activity to Russian and Chinese threat actors. The campaigns used Claude to generate content at scale for influence operations, likely including translation, persona management, and content variation tasks that make manual attribution harder. This is a significant public disclosure because it confirms that frontier AI models are now an operational tool in state-sponsored information warfare — not a theoretical risk. For defenders working in threat intelligence, content moderation, or brand protection, the implication is clear: AI-generated disinformation campaigns are cheaper, faster, and more linguistically polished than ever. Anthropic's willingness to name nation-state actors and publish details is unusual in the industry and sets a useful precedent for transparency.
Schrödinger's Feed
Scientists have observed gravitational effects on quantum systems for the first time, lending experimental weight to the idea that time itself may carry a fundamental, irreducible uncertainty at quantum scales — a consequence of the intersection between general relativity and quantum mechanics. The finding suggests there may be an absolute physical limit to clock precision, independent of engineering constraints. For the cryptography community, this is a slow-burn story: if time measurement has an intrinsic quantum floor, it eventually touches assumptions embedded in timing-based protocols, synchronisation systems, and future quantum key distribution networks. It won't rewrite your threat model this quarter, but practitioners building long-horizon cryptographic infrastructure should keep one eye on where quantum gravity research and applied timekeeping intersect.
/dev/random
An ongoing catalogue of AI mathematical "misalignments" has been quietly growing at mathandai.org, documenting cases where AI systems produce confidently wrong answers to formally verifiable mathematical problems — not approximation errors, but structurally incorrect reasoning that the model presents as rigorous proof. The failure mode is particularly striking because mathematics is one domain where ground truth is unambiguous, making the errors impossible to explain away as subjective interpretation. Some examples involve models introducing phantom variables mid-proof or reaching correct conclusions via internally contradictory steps. For anyone currently deploying AI assistants in code review, vulnerability analysis, or cryptographic verification workflows: if the model can't reliably tell you whether a proof is valid, it probably can't reliably tell you whether your authentication logic is sound either.