← All briefings

Google Chromium V8 · PowerJob Worker · SonicWall Network Security Manager

Date: 2026-09-05 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

Google Chrome’s V8 vulnerability CVE-2026-85046 has been added to the CISA KEV catalog following confirmed exploitation and should be treated as the highest-priority endpoint action. New critical exposure also affects PowerJob, SonicWall Network Security Manager, ASUS Control Center and Nango deployments. German authorities additionally reported a TerminalFix campaign compromising a state institution, with attempted ransomware deployment.

Critical Vulnerabilities

CVE-2026-85046 — Google Chromium V8

  • Severity: CVSS 8.8
  • EPSS: Not available
  • Technical detail: A type-confusion vulnerability in the V8 JavaScript and WebAssembly engine allows remote code execution through a crafted HTML page. Successful exploitation can provide code execution inside the browser sandbox and may affect Chromium-based browsers, including Chrome, Microsoft Edge and Opera.
  • Exploitation status: Actively exploited; added to the CISA KEV catalog on 2026-09-04.
  • Remediation: Update Chrome to 152.0.7977.82 or later, and apply corresponding security updates for Chromium-based browsers. Confirm update deployment across managed endpoints and investigate browser crashes, suspicious child processes and exploit-related telemetry.

CVE-2026-75430 — PowerJob Worker

  • Severity: CVSS 9.8
  • EPSS: Not available
  • Technical detail: PowerJob Worker version 5.1.2 and likely earlier versions expose the /worker/deployContainer endpoint without authentication on the default transport port. A remote attacker may use the endpoint to execute arbitrary code, making internet-exposed workers and flat internal deployments particularly high risk.
  • Exploitation status: No exploitation reported in the supplied intelligence.
  • Remediation: Upgrade to a vendor-fixed release when available. Until then, remove worker ports from untrusted networks, restrict access to authorized PowerJob components and monitor for unexpected container creation, commands and outbound connections. Also assess the related predictable-JWT issue CVE-2026-75431.

CVE-2026-78327 — SonicWall Network Security Manager

  • Severity: CVSS 9.1
  • EPSS: Not available
  • Technical detail: An OS command-injection vulnerability affects the on-premises Network Security Manager interface through version 4.3.0. Exploitation could allow an authenticated attacker to execute commands on the management system; exposure is increased where the administrative interface is reachable from user or internet networks.
  • Exploitation status: No exploitation reported in the supplied intelligence.
  • Remediation: Apply SonicWall’s security update for NSM. Restrict management access to dedicated administration networks, review administrator activity and inspect the host for unusual processes, scheduled tasks, file changes and outbound traffic. Review CVE-2026-78328 and CVE-2026-81939 in the same product family.

CVE-2026-9317 — Nango

  • Severity: CVSS 9.2
  • EPSS: 0 — no exploitation probability currently reported
  • Technical detail: Nango versions before 0.71.6 expose an unauthenticated runner tRPC server. Remote attackers may invoke the exposed start functionality to execute arbitrary JavaScript, potentially compromising integration credentials and the host running Nango.
  • Exploitation status: No exploitation reported in the supplied intelligence.
  • Remediation: Upgrade to Nango 0.71.6 or later. Restrict runner-server access, rotate integration secrets if exposure is possible and review recent workflow executions, child processes, code changes and outbound connections.

CVE-2026-75754 — ASUS Control Center Enterprise

  • Severity: CVSS 10.0
  • EPSS: 0 — no exploitation probability currently reported
  • Technical detail: ASUS Control Center Enterprise versions up to 4.0.0.2 are affected by missing authentication, SSRF and hard-coded credential issues. The combined weaknesses may allow an unauthorized user to obtain an encryption key and potentially access management functions or protected assets.
  • Exploitation status: No exploitation reported in the supplied intelligence.
  • Remediation: Apply the ASUS security update or mitigation. Remove Control Center interfaces from internet exposure, restrict administrative access and rotate credentials or keys that may have been accessible. Review server logs for unauthorized requests, SSRF activity and unusual management operations.

ONGOING

  • CVE-2026-63520 (Microsoft SharePoint): Active exploitation and public PoC remain reported; patch and inspect for web shells.
  • CVE-2026-19490 (Citrix NetScaler): Attacks are now reported; verify patching and management-interface restrictions.
  • CVE-2026-81578 / CVE-2026-82078 (PaperCut): Chained exploitation remains reported; patch before the 2026-09-14 KEV deadline.
  • CVE-2026-85046 (Chromium V8): KEV-listed and actively exploited; browser updates are mandatory.
  • CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000): Active exploitation remains reported; patch and assess for compromise.
  • CVE-2026-0768 (Langflow): Active exploitation remains reported; upgrade and rotate exposed credentials.
  • CVE-2026-60004, CVE-2026-49869, CVE-2026-82329 and CVE-2026-9586: KEV remediation remains required; deadlines have passed or are due immediately.

European Advisories

  • WID-SEC-2026-3189 (vm2): New critical BSI advisory reports multiple flaws enabling arbitrary code execution and integrity compromise. Update or remove affected vm2 deployments, particularly where untrusted JavaScript is processed.
  • WID-SEC-2026-3186 (Microsoft cloud services): New high-severity advisory covers security-control bypass, privilege escalation, information disclosure and service or data impact across multiple cloud services. Apply Microsoft mitigations and review affected tenant activity. Related Microsoft identity issues remain covered in the previous report.
  • WID-SEC-2026-3184 (Dell Secure Connect Gateway): Multiple high-impact flaws may enable unauthorized access, command or SQL injection, container escape, root-level privilege escalation and remote code execution. Prioritize exposed gateways and apply Dell updates.
  • WID-SEC-2026-3177 (Kibana): Authenticated vulnerabilities may permit privilege escalation, data manipulation, disclosure and denial of service. Update internet-facing and administrator-accessible Kibana instances.
  • WID-SEC-2026-3173 (MISP): Covered by new CVE-2026-85546 in Critical Vulnerabilities only if prioritized for deployment; otherwise update MISP and restrict administrative access.
  • BSI updates for GNU libc, Linux Kernel, PostgreSQL, Go, OpenSSL and related Linux components remain relevant to maintenance teams; reassess affected inventories and apply current vendor fixes.

Active Threats and Campaigns

  • TerminalFix campaign — NEW: BSI reported compromise of a German state institution consistent with Microsoft’s TerminalFix campaign. The activity reportedly included attempts to deploy ransomware. Hunt for suspicious remote terminal activity, unauthorized persistence, lateral movement and ransomware precursors; preserve affected systems for forensic review.
  • Ted backdoor / curlRAT — NEW: Rapid7 identified a Linux toolkit targeting South Korean media and automotive organizations. Trojanized HAProxy and system binaries enabled command execution, web-traffic interception and credential harvesting. Validate HAProxy and system-binary integrity and investigate unexpected binary modifications.
  • Chrome exploitation — STATUS CHANGE: CVE-2026-85046 is now CISA KEV-listed and actively exploited; accelerate browser patching and endpoint hunting.
  • RMM phishing, Node.js malware delivery, developer supply-chain compromise, Langflow exploitation and the Virtualizor malicious-update campaign remain ongoing without material new developments.

Security News and Context

  1. Deploy Chrome/Chromium updates addressing actively exploited CVE-2026-85046.
  2. Identify and isolate exposed PowerJob workers; assess CVE-2026-75430 and CVE-2026-75431.
  3. Patch SonicWall NSM, ASUS Control Center and Nango; restrict management interfaces immediately.
  4. Investigate German and European environments for TerminalFix indicators, ransomware staging and suspicious remote-terminal activity.
  5. Validate HAProxy and Linux system-binary integrity where relevant to the Ted backdoor campaign.
  6. Review PostgreSQL replication-role assignments and apply current updates.
  7. Continue remediation of previously reported items: SharePoint, Citrix NetScaler, PaperCut, Gitea, Langflow, SonicWall SMA1000, ownCloud, GitLab, SQL Server and Linux Kernel vulnerabilities.