⌂

🐞 CVE Tracking and Search

Search and filter Common Vulnerabilities and Exposures

← Dashboard CVE Search Exploitation Radar Breaches Trends Industries Vendors MITRE ATT&CK MITRE ATLAS Threat Actors Attack-Tools Alerts Investigations
🔎 Search & Filters
Search: Time Range:
Sources:
📚 Intelligence Coverage the corpus behind every search on this page
380,160+
CVEs Tracked
380,160
Exploit Intel
362,085
EPSS Scored
5,297
CISA KEV
2,704
Metasploit Modules
30,390
ExploitDB Entries
61
MITRE ATT&CK Maps
🚨 Exploitation Status within the current filter · click a card to jump to it
0
Actively Exploited
2
CISA KEV
19
PoC Available
0
Zero-Days
8
Recent Discoveries
1
Most Mentioned
📊 CVE Severity Distribution last 30 days
🐞 Results 1,399 CVEs in the last 30 days · showing 101-150
CVE-2026-95346 MEDIUM CVSS: 4.8 EPSS: 0.3% CWE-451
UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95346: UI misrepresentation in Chromoting
MSRC Security Update Guide
CVE-2026-95332 MEDIUM CVSS: 4.7 EPSS: 0.3% CWE-457
Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95332: Use of uninitialized variable in Tint
MSRC Security Update Guide
CVE-2026-95358 MEDIUM CVSS: 4.4 EPSS: 0.1% CWE-863 T1078
Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95358: Incorrect authorization in Mobile
MSRC Security Update Guide
CVE-2026-95289 MEDIUM CVSS: 4.3 EPSS: 0.2% CWE-863 T1078
Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95289: Incorrect authorization in Scroll
MSRC Security Update Guide
CVE-2026-95296 MEDIUM CVSS: 4.3 EPSS: 0.2% CWE-862 T1078
Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95296: Missing authorization in Core
MSRC Security Update Guide
CVE-2026-95342 MEDIUM CVSS: 4.3 EPSS: 0.3% CWE-862 T1078
Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95342: Missing authorization in V8
MSRC Security Update Guide
CVE-2026-95368 MEDIUM CVSS: 4.3 EPSS: 0.2% CWE-863 T1078
Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95368: Incorrect authorization in DevTools
MSRC Security Update Guide
CVE-2026-95308 LOW CVSS: 3.4 EPSS: 0.2% CWE-190 T1203
Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95308: Integer overflow in Metrics
MSRC Security Update Guide
CVE-2026-95324 LOW CVSS: 3.4 EPSS: 0.3% CWE-908 T1005
Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95324: Uninitialized resource in GPU
MSRC Security Update Guide
CVE-2026-95359 LOW CVSS: 3.4 EPSS: 0.3% CWE-908 T1005
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95359: Uninitialized resource in GPU
MSRC Security Update Guide
CVE-2026-95312 LOW CVSS: 3.1 EPSS: 0.2% CWE-200 T1005 T1083
Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95312: Information leak in Passwords
MSRC Security Update Guide
CVE-2026-95317 LOW CVSS: 3.1 EPSS: 0.2% CWE-863 T1078
Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95317: Incorrect authorization in MediaCapture
MSRC Security Update Guide
CVE-2026-95302 LOW CVSS: 2.9 EPSS: 0.1% CWE-863 T1078
Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95302: Incorrect authorization in WebAPKs
MSRC Security Update Guide
CVE-2026-95316 LOW CVSS: 2.9 EPSS: 0.1% CWE-252
Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95316: Unchecked return value in Performance
MSRC Security Update Guide
CVE-2026-95277 UNKNOWN EPSS: 0.5%
Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95277: Use after free in Views
MSRC Security Update Guide
CVE-2026-95287 UNKNOWN EPSS: 0.2%
Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95287: Missing authorization in Navigation
MSRC Security Update Guide
CVE-2026-95292 UNKNOWN EPSS: 0.2%
Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95292: Incorrect authorization in Safebrowsing
MSRC Security Update Guide
CVE-2026-95293 UNKNOWN EPSS: 0.3%
Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95293: Uninitialized resource in GPU
MSRC Security Update Guide
CVE-2026-95295 UNKNOWN EPSS: 0.1%
Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physical access. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95295: Information leak in Mobile
MSRC Security Update Guide
CVE-2026-95298 UNKNOWN EPSS: 0.2%
Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95298: Use after free in Browser
MSRC Security Update Guide
CVE-2026-95309 UNKNOWN EPSS: 0.3%
UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95309: UI misrepresentation in Mobile
MSRC Security Update Guide
CVE-2026-95313 UNKNOWN EPSS: 0.5%
Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95313: Use after free in Fullscreen
MSRC Security Update Guide
CVE-2026-95326 UNKNOWN EPSS: 0.3%
Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95326: Incomplete cleanup in Bluetooth
MSRC Security Update Guide
CVE-2026-95327 UNKNOWN EPSS: 0.3%
Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95327: Information leak in Networking
MSRC Security Update Guide
CVE-2026-95338 UNKNOWN EPSS: 0.4%
Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95338: Use after free in PDFium
MSRC Security Update Guide
CVE-2026-95340 UNKNOWN EPSS: 0.3%
Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95340: Incorrect authorization in PictureInPicture
MSRC Security Update Guide
CVE-2026-95361 UNKNOWN EPSS: 0.3%
Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95361: Confused deputy in DevTools
MSRC Security Update Guide
CVE-2026-95366 UNKNOWN EPSS: 0.3%
Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95366: Use of released resource in Core
MSRC Security Update Guide
CVE-2026-95374 UNKNOWN EPSS: 0.3%
Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95374: Incorrect authorization in Network
MSRC Security Update Guide
CVE-2026-95375 UNKNOWN EPSS: 0.2%
Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95375: Incorrect authorization in BrowserTag
MSRC Security Update Guide
CVE-2026-95376 UNKNOWN EPSS: 0.2%
Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95376: Externally controlled reference in DevTools
MSRC Security Update Guide
CVE-2026-95382 UNKNOWN EPSS: 0.3%
Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95382: Improper input validation in Auth
MSRC Security Update Guide
CVE-2026-95384 UNKNOWN EPSS: 0.2%
Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95384: Race condition in Transactions Platform
MSRC Security Update Guide
CVE-2026-95385 UNKNOWN EPSS: 0.3%
Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Mentioned in 1 article(s):
Chromium CVE-2026-95385: Inappropriate implementation in PlatformIntegration
MSRC Security Update Guide
CVE-2026-100206 UNKNOWN
CVE details not yet enriched from NVD
Published: Unknown
Mentioned in 1 article(s):
CVE-2026-100206 Microsoft Office Information Disclosure Vulnerability
MSRC Security Update Guide
CVE-2026-48842 HIGH CVSS: 8.1 EPSS: 0.9% VulnCheck KEV PoC Available CWE-89 T1190
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
Published: 2026-05-25
Mentioned in 2 article(s):
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Hacker News
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
SecurityWeek
CVE-2025-2135 HIGH CVSS: 8.8 EPSS: 7.0% CWE-843
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2025-03-10
Mentioned in 1 article(s):
Chromium: CVE-2025-2135 Type Confusion in V8
MSRC Security Update Guide
CVE-2026-86060 CRITICAL CVSS: 9.8 EPSS: 1.8% VulnCheck KEV Weaponized ExploitDB CWE-88
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Published: 2026-09-05
Mentioned in 3 article(s):
CVE-2026-67279 - Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Recent KEV Entries
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
The Hacker News
CVE-2026-86060 - MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
Recent KEV Entries
CVE-2026-87902 HIGH CVSS: 8.1 EPSS: 19.8% VulnCheck KEV Weaponized ExploitDB CWE-98
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Published: 2026-09-22
Mentioned in 4 article(s):
CVE-2026-87902 - WordPress Core Remote File Inclusion Vulnerability
Recent KEV Entries
Critical WordPress Vulnerability Exploited Immediately After Disclosure
SecurityWeek
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
The Hacker News
Hackers start exploiting critical WordPress flaw for code execution
BleepingComputer
CVE-2026-67279 MEDIUM CVSS: 6.5 EPSS: 1.0% VulnCheck KEV Weaponized CWE-841
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Published: 2026-09-05
Mentioned in 2 article(s):
CVE-2026-67279 - Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Recent KEV Entries
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
The Hacker News
CVE-2026-28324 CRITICAL CVSS: 9.8 EPSS: 0.7% CWE-345
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.
Published: 2026-09-22
Mentioned in 1 article(s):
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
SecurityWeek
CVE-2026-28325 HIGH CVSS: 8.8 EPSS: 1.5% CWE-502 T1203
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
Published: 2026-09-22
Mentioned in 1 article(s):
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
SecurityWeek
CVE-2026-71362 CRITICAL CVSS: 9.1 EPSS: 87.5% VulnCheck KEV Weaponized CWE-863 T1078
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
Published: 2026-08-11
Mentioned in 1 article(s):
CVE-2026-71362 - Adobe Commerce and Magento Incorrect Authorization Vulnerability
Recent KEV Entries
CVE-2026-85102 CRITICAL CVSS: 9.8 EPSS: 7.5% VulnCheck KEV Weaponized CWE-295 T1557
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Published: 2026-09-09
Mentioned in 4 article(s):
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
BleepingComputer
CVE-2026-85102 - Check Point Multiple Products Improper Certificate Validation Vulnerability
Recent KEV Entries
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
BleepingComputer
Check Point Patches Critical VPN Vulnerabilities
SecurityWeek
CVE-2026-70125 HIGH CVSS: 8.8 EPSS: 0.4% CWE-122 T1203
Microsoft Office Outlook Remote Code Execution Vulnerability
Published: 2026-09-23
Mentioned in 1 article(s):
CVE-2026-70125 Microsoft Outlook Remote Code Execution Vulnerability
MSRC Security Update Guide
CVE-2026-80521 HIGH CVSS: 7.8 EPSS: 0.2%
In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A <-> B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a small window where unix_add_edges() publishes a new edge (B <-> B) to GC but its skb is not queued by skb_queue_tail(). If 2-2) completes before skb_queue_tail() and GC is triggered, it judges A <-> B as dead, but B is not freed because GC cannot collect the not-yet-queued skb holding the B <-> B edge. X -. A <-> B -. This edge is visible ^--' ^..' but skb is not This itself is not a problem since the next GC run will judge B as dead as well and free it finally. X -. A <.> B -. ^--' ^--' However, X's SCC forces the next GC to call unix_walk_scc_fast(), and it iterates over A through B's scc_entry. Let's unlink scc_entry before freeing the vertex in unix_del_edge().
Published: 2026-08-26
Mentioned in 1 article(s):
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
The Hacker News
CVE-2026-87536 HIGH CVSS: 8.8 EPSS: 0.4% CWE-416 T1203
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Mentioned in 1 article(s):
Chromium CVE-2026-87536: Use after free in V8
MSRC Security Update Guide
CVE-2026-94127 CRITICAL CVSS: 9.8 EPSS: 2.2% VulnCheck KEV Weaponized CWE-122 T1203
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published: 2026-09-22
Mentioned in 2 article(s):
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
The Hacker News
CVE-2026-94127 - F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
Recent KEV Entries
CVE-2026-85046 HIGH CVSS: 8.8 EPSS: 48.9% VulnCheck KEV Weaponized CWE-843
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-03
Mentioned in 2 article(s):
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
The Hacker News
Chromium: CVE-2026-85046 Type confusion in V8
MSRC Security Update Guide
CVE-2026-87491 HIGH CVSS: 8.8 EPSS: 3.1% VulnCheck KEV Weaponized CWE-787 T1203
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Mentioned in 4 article(s):
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
The Hacker News
Chromium CVE-2026-87491: Out of bounds write in V8
MSRC Security Update Guide
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
The Hacker News
CVE-2026-87491 - Google Chromium V8 Out of Bounds Write Vulnerability
Recent KEV Entries