Security NEXT•September 9, 2026•🇯🇵Translated from Japanese

Google Releases Chrome 153 Fixing 230 Vulnerabilities Including Zero-Day Exploit

Google has released Chrome 153 on September 8, 2026, addressing a total of 230 vulnerabilities, including a zero-day flaw already under active exploitation.

The update ships as version 153.0.8010.37 and 153.0.8010.36 for Windows and macOS, and 153.0.8010.36 for Linux. Five issues rated Critical were resolved, covering use-after-free vulnerabilities in WebGL (CVE-2026-87464 and CVE-2026-87488), an out-of-bounds write (CVE-2026-87438), a buffer overflow (CVE-2026-87527), and a use-after-free in the Cast component (CVE-2026-87628).

Additional high-severity fixes were applied across multiple components including ANGLE, PDFium, V8, DevTools, Web Authentication, and Payments. The medium-severity zero-day CVE-2026-87491 in the V8 engine involves an out-of-bounds write and was reported on August 6, 2026; exploitation has already been confirmed.

Full list of patched CVEs

Critical: CVE-2026-87438, CVE-2026-87464, CVE-2026-87488, CVE-2026-87527, CVE-2026-87628

High: CVE-2026-87440, CVE-2026-87444, CVE-2026-87447, CVE-2026-87460, CVE-2026-87467, CVE-2026-87474, CVE-2026-87480, CVE-2026-87492, CVE-2026-87498, CVE-2026-87499, CVE-2026-87500, CVE-2026-87512, CVE-2026-87514, CVE-2026-87517, CVE-2026-87520, CVE-2026-87524, CVE-2026-87525, CVE-2026-87536, CVE-2026-87542, CVE-2026-87552, CVE-2026-87554, CVE-2026-87558, CVE-2026-87564, CVE-2026-87569, CVE-2026-87572, CVE-2026-87578, CVE-2026-87581, CVE-2026-87585, CVE-2026-87587, CVE-2026-87596, CVE-2026-87604, CVE-2026-87607, CVE-2026-87612, CVE-2026-87621, CVE-2026-87633, CVE-2026-87639, CVE-2026-87646, CVE-2026-87647, CVE-2026-87650, CVE-2026-87651, CVE-2026-87654

Medium: CVE-2026-87431 through CVE-2026-87658 (115 CVEs total, including the exploited CVE-2026-87491)

Low: CVE-2026-87429, CVE-2026-87430, CVE-2026-87437 and 48 additional low-severity issues

Google plans to complete the staged rollout over the next several days to weeks.

Related articles

Hispasec•Vulnerabilities & Exploits

Automated Scans Exploit CVE-2026-39364 in Exposed Vite Dev Servers to Steal AWS and Azure Secrets

A large-scale automated campaign is actively scanning the internet for publicly exposed Vite development servers to exfiltrate sensitive files and cloud credentials. Attackers leverage CVE-2026-39364 to bypass server.fs.deny restrictions and read arbitrary files using crafted query parameters such as ?raw combined with ?import. The campaign has generated thousands of requests over several weeks, with telemetry from honeypots recording 807 sessions and roughly 32,000 events in a single month. Targets include .env files, terraform.tfstate, and other infrastructure-as-code artifacts that often contain AWS access keys and Microsoft Azure tokens. The vulnerable versions are Vite 7.1.0 through versions prior to 7.3.2 and Vite 8.x prior to 8.0.5. Part of the scanning traffic originates from Google Cloud IP ranges 34.x and 35.x. Organizations are urged to update immediately, restrict the dev server to localhost, and rotate any exposed cloud credentials.

Habr•Vulnerabilities & Exploits

cKEV Index Launches to Prioritize Vulnerabilities Using Urgent Patch Score Methodology

CyberOK has introduced the open cKEV Index, a catalog of high-priority vulnerabilities based on the Urgent Patch Score (UPS) framework that tracks signals such as exploit publication and confirmed attacks. The index addresses the growing gap between accelerated vulnerability discovery powered by AI and the slower pace of patching, testing, and deployment in real environments. It incorporates timelines from sources including Anthropic reports on AI-assisted campaigns GTG-50014 and GTG-50029, the rust-in-peace framework, Microsoft Exchange Server Subscription Edition delays, and Oracle’s record 1,434 CVE fixes. UPS defines progressive phases from Radar to Emergency/IR, allowing teams to link specific events like PoC releases or CISA KEV additions to concrete actions under resource constraints. Research using 2025 CISA KEV data shows that early signals enable 35–53% of patches to be completed before official exploitation confirmation. The public version displays only Urgent Patch and Emergency stages with event histories, while full data and API access are available to CyberOK customers.

Security NEXT•Vulnerabilities & Exploits

Multiple Vulnerabilities Found in WatchGuard Access Points Including Critical Flaw

WatchGuard Technologies has disclosed three vulnerabilities affecting its WatchGuard AP access point products, one of which is rated critical. The issues were detailed in an advisory published on September 28 and involve flaws in internal API services and a diagnostic command-line interface. CVE-2026-86102 allows OS command injection that can lead to arbitrary shell command execution on the underlying operating system when an attacker has network access. CVE-2026-101891 stems from improper access controls that permit unauthenticated acquisition of valid API sessions. CVE-2026-87969 affects the diagnostic CLI and enables arbitrary OS command execution but requires administrator privileges to exploit. The findings were reported by Security NEXT.

BoletimSec•Vulnerabilities & Exploits

CISA Adds Two Critical Citrix NetScaler Flaws to Known Exploited Vulnerabilities Catalog

The CISA has added two critical vulnerabilities affecting Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities catalog following reports of active global exploitation. Both CVE-2026-88771 and CVE-2026-88772 carry a CVSS score of 9.5 and were patched by Citrix on September 27, the same day they were added to the catalog. The first flaw stems from improper input validation and allows unauthenticated arbitrary command execution on default installations. The second issue involves a buffer overflow that can lead to remote code execution or denial of service when DTLS is enabled on VPN virtual servers. Affected versions include 14.1-73.32, 13.1-63.21 and earlier, with fixes available in 14.1-73.37, 13.1-64.23 and later releases including FIPS variants. The issues were identified by watchTowr on September 26, and Citrix confirmed ongoing attacks against unpatched systems. Organizations are advised to apply patches immediately while preserving evidence and following full incident response procedures.