Google Releases Chrome 153 Fixing 230 Vulnerabilities Including Zero-Day Exploit
Google has released Chrome 153 on September 8, 2026, addressing a total of 230 vulnerabilities, including a zero-day flaw already under active exploitation.
The update ships as version 153.0.8010.37 and 153.0.8010.36 for Windows and macOS, and 153.0.8010.36 for Linux. Five issues rated Critical were resolved, covering use-after-free vulnerabilities in WebGL (CVE-2026-87464 and CVE-2026-87488), an out-of-bounds write (CVE-2026-87438), a buffer overflow (CVE-2026-87527), and a use-after-free in the Cast component (CVE-2026-87628).
Additional high-severity fixes were applied across multiple components including ANGLE, PDFium, V8, DevTools, Web Authentication, and Payments. The medium-severity zero-day CVE-2026-87491 in the V8 engine involves an out-of-bounds write and was reported on August 6, 2026; exploitation has already been confirmed.
Full list of patched CVEs
Critical: CVE-2026-87438, CVE-2026-87464, CVE-2026-87488, CVE-2026-87527, CVE-2026-87628
High: CVE-2026-87440, CVE-2026-87444, CVE-2026-87447, CVE-2026-87460, CVE-2026-87467, CVE-2026-87474, CVE-2026-87480, CVE-2026-87492, CVE-2026-87498, CVE-2026-87499, CVE-2026-87500, CVE-2026-87512, CVE-2026-87514, CVE-2026-87517, CVE-2026-87520, CVE-2026-87524, CVE-2026-87525, CVE-2026-87536, CVE-2026-87542, CVE-2026-87552, CVE-2026-87554, CVE-2026-87558, CVE-2026-87564, CVE-2026-87569, CVE-2026-87572, CVE-2026-87578, CVE-2026-87581, CVE-2026-87585, CVE-2026-87587, CVE-2026-87596, CVE-2026-87604, CVE-2026-87607, CVE-2026-87612, CVE-2026-87621, CVE-2026-87633, CVE-2026-87639, CVE-2026-87646, CVE-2026-87647, CVE-2026-87650, CVE-2026-87651, CVE-2026-87654
Medium: CVE-2026-87431 through CVE-2026-87658 (115 CVEs total, including the exploited CVE-2026-87491)
Low: CVE-2026-87429, CVE-2026-87430, CVE-2026-87437 and 48 additional low-severity issues
Google plans to complete the staged rollout over the next several days to weeks.
Related articles
Asset and Vulnerability Management in Practice: Building a Working Process with MaxPatrol VM and NetBox
This detailed guide explains how organizations can implement effective asset and vulnerability management by focusing on reliable infrastructure data, IT collaboration, and automation. It draws from real-world projects using MaxPatrol VM, NetBox, and 1C:ERP to demonstrate dynamic grouping, webhook-driven asset onboarding, and deviation-based control. The approach emphasizes eight core principles including minimizing human dependency, just-in-time awareness, maximum data accuracy, and embedding security into existing IT workflows. Technical flows cover automatic scanning initiation upon asset creation in NetBox, categorization against unacceptable events, and priority-based patching cycles aligned with Patch Tuesday. Self-control mechanisms and PDQL queries enable ongoing validation of subnets, asset freshness, and compliance without excessive manual oversight. The framework is designed to be adaptable to any mature vulnerability management platform beyond the specific tools demonstrated.
Microsoft Addresses 973 Vulnerabilities in September Security Update
Microsoft released its monthly security updates on September 8, 2026, fixing 973 vulnerabilities tracked by CVE identifiers. The release coincided with Patch Tuesday and also resolved four third-party software flaws. Affected products span Windows, Office, SQL Server, Azure, Microsoft Dynamics, SharePoint Server, and various development tools. Among the issues, 258 allow remote code execution and 438 enable privilege escalation. A total of 113 vulnerabilities received the highest severity rating of Critical, while the remaining 860 were rated Important. Several of the flaws have already been observed in active exploitation.
Microsoft Releases Record 966 Patches in Largest Patch Tuesday Ever, Including Two Actively Exploited Zero-Days
Microsoft has issued its largest monthly security update to date, addressing 966 vulnerabilities across Windows and related products during the September Patch Tuesday. The release includes two zero-day flaws already exploited in real-world attacks: CVE-2026-81963 in the Windows Update stack and CVE-2026-85880 in the Windows ALPC mechanism, both enabling local privilege escalation to SYSTEM level. A total of 105 vulnerabilities received critical severity ratings, with the majority involving privilege escalation (438) and remote code execution (258). An additional 204 issues were fixed earlier in September across Azure, Entra ID, Edge, and other services. The surge in patched flaws coincides with Microsoft's deployment of an AI-assisted vulnerability discovery system. Previous months saw significantly lower volumes, with 570 fixes in July and 400 in August.
Adobe Issues Critical Security Updates for ColdFusion Fixing Nine CVEs Including Eval Injection Flaws
Adobe has released security updates for Adobe ColdFusion to address nine vulnerabilities, urging users to apply the patches immediately. The update coincides with Patch Tuesday on September 8, 2026, and covers issues such as Eval injection, SQL injection, cross-site scripting, and access control weaknesses. Six of the vulnerabilities are rated Critical, with the highest CVSS v3.1 base score reaching 9.9 for CVE-2026-48273. The remaining three vulnerabilities are classified as Important. Adobe ColdFusion users are advised to update without delay to mitigate risks of code injection and unauthorized access. The advisory also references related security issues in other products including Canva, BIG-IP, and Dell SCG.