Google Chromium V8 · PowerJob Worker · SonicWall Network Security Manager
Date: 2026-09-05 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
Google Chrome’s V8 vulnerability CVE-2026-85046 has been added to the CISA KEV catalog following confirmed exploitation and should be treated as the highest-priority endpoint action. New critical exposure also affects PowerJob, SonicWall Network Security Manager, ASUS Control Center and Nango deployments. German authorities additionally reported a TerminalFix campaign compromising a state institution, with attempted ransomware deployment.
Critical Vulnerabilities
CVE-2026-85046 — Google Chromium V8
- Severity: CVSS 8.8
- EPSS: Not available
- Technical detail: A type-confusion vulnerability in the V8 JavaScript and WebAssembly engine allows remote code execution through a crafted HTML page. Successful exploitation can provide code execution inside the browser sandbox and may affect Chromium-based browsers, including Chrome, Microsoft Edge and Opera.
- Exploitation status: Actively exploited; added to the CISA KEV catalog on 2026-09-04.
- Remediation: Update Chrome to
152.0.7977.82or later, and apply corresponding security updates for Chromium-based browsers. Confirm update deployment across managed endpoints and investigate browser crashes, suspicious child processes and exploit-related telemetry.
CVE-2026-75430 — PowerJob Worker
- Severity: CVSS 9.8
- EPSS: Not available
- Technical detail: PowerJob Worker version 5.1.2 and likely earlier versions expose the
/worker/deployContainerendpoint without authentication on the default transport port. A remote attacker may use the endpoint to execute arbitrary code, making internet-exposed workers and flat internal deployments particularly high risk. - Exploitation status: No exploitation reported in the supplied intelligence.
- Remediation: Upgrade to a vendor-fixed release when available. Until then, remove worker ports from untrusted networks, restrict access to authorized PowerJob components and monitor for unexpected container creation, commands and outbound connections. Also assess the related predictable-JWT issue
CVE-2026-75431.
CVE-2026-78327 — SonicWall Network Security Manager
- Severity: CVSS 9.1
- EPSS: Not available
- Technical detail: An OS command-injection vulnerability affects the on-premises Network Security Manager interface through version 4.3.0. Exploitation could allow an authenticated attacker to execute commands on the management system; exposure is increased where the administrative interface is reachable from user or internet networks.
- Exploitation status: No exploitation reported in the supplied intelligence.
- Remediation: Apply SonicWall’s security update for NSM. Restrict management access to dedicated administration networks, review administrator activity and inspect the host for unusual processes, scheduled tasks, file changes and outbound traffic. Review
CVE-2026-78328andCVE-2026-81939in the same product family.
CVE-2026-9317 — Nango
- Severity: CVSS 9.2
- EPSS: 0 — no exploitation probability currently reported
- Technical detail: Nango versions before 0.71.6 expose an unauthenticated runner tRPC server. Remote attackers may invoke the exposed
startfunctionality to execute arbitrary JavaScript, potentially compromising integration credentials and the host running Nango. - Exploitation status: No exploitation reported in the supplied intelligence.
- Remediation: Upgrade to Nango 0.71.6 or later. Restrict runner-server access, rotate integration secrets if exposure is possible and review recent workflow executions, child processes, code changes and outbound connections.
CVE-2026-75754 — ASUS Control Center Enterprise
- Severity: CVSS 10.0
- EPSS: 0 — no exploitation probability currently reported
- Technical detail: ASUS Control Center Enterprise versions up to 4.0.0.2 are affected by missing authentication, SSRF and hard-coded credential issues. The combined weaknesses may allow an unauthorized user to obtain an encryption key and potentially access management functions or protected assets.
- Exploitation status: No exploitation reported in the supplied intelligence.
- Remediation: Apply the ASUS security update or mitigation. Remove Control Center interfaces from internet exposure, restrict administrative access and rotate credentials or keys that may have been accessible. Review server logs for unauthorized requests, SSRF activity and unusual management operations.
ONGOING
CVE-2026-63520(Microsoft SharePoint): Active exploitation and public PoC remain reported; patch and inspect for web shells.CVE-2026-19490(Citrix NetScaler): Attacks are now reported; verify patching and management-interface restrictions.CVE-2026-81578/CVE-2026-82078(PaperCut): Chained exploitation remains reported; patch before the 2026-09-14 KEV deadline.CVE-2026-85046(Chromium V8): KEV-listed and actively exploited; browser updates are mandatory.CVE-2026-83548/CVE-2026-83549(SonicWall SMA1000): Active exploitation remains reported; patch and assess for compromise.CVE-2026-0768(Langflow): Active exploitation remains reported; upgrade and rotate exposed credentials.CVE-2026-60004,CVE-2026-49869,CVE-2026-82329andCVE-2026-9586: KEV remediation remains required; deadlines have passed or are due immediately.
European Advisories
WID-SEC-2026-3189(vm2): New critical BSI advisory reports multiple flaws enabling arbitrary code execution and integrity compromise. Update or remove affected vm2 deployments, particularly where untrusted JavaScript is processed.WID-SEC-2026-3186(Microsoft cloud services): New high-severity advisory covers security-control bypass, privilege escalation, information disclosure and service or data impact across multiple cloud services. Apply Microsoft mitigations and review affected tenant activity. Related Microsoft identity issues remain covered in the previous report.WID-SEC-2026-3184(Dell Secure Connect Gateway): Multiple high-impact flaws may enable unauthorized access, command or SQL injection, container escape, root-level privilege escalation and remote code execution. Prioritize exposed gateways and apply Dell updates.WID-SEC-2026-3177(Kibana): Authenticated vulnerabilities may permit privilege escalation, data manipulation, disclosure and denial of service. Update internet-facing and administrator-accessible Kibana instances.WID-SEC-2026-3173(MISP): Covered by newCVE-2026-85546in Critical Vulnerabilities only if prioritized for deployment; otherwise update MISP and restrict administrative access.- BSI updates for GNU libc, Linux Kernel, PostgreSQL, Go, OpenSSL and related Linux components remain relevant to maintenance teams; reassess affected inventories and apply current vendor fixes.
Active Threats and Campaigns
- TerminalFix campaign — NEW: BSI reported compromise of a German state institution consistent with Microsoft’s TerminalFix campaign. The activity reportedly included attempts to deploy ransomware. Hunt for suspicious remote terminal activity, unauthorized persistence, lateral movement and ransomware precursors; preserve affected systems for forensic review.
- Ted backdoor / curlRAT — NEW: Rapid7 identified a Linux toolkit targeting South Korean media and automotive organizations. Trojanized HAProxy and system binaries enabled command execution, web-traffic interception and credential harvesting. Validate HAProxy and system-binary integrity and investigate unexpected binary modifications.
- Chrome exploitation — STATUS CHANGE:
CVE-2026-85046is now CISA KEV-listed and actively exploited; accelerate browser patching and endpoint hunting. - RMM phishing, Node.js malware delivery, developer supply-chain compromise, Langflow exploitation and the Virtualizor malicious-update campaign remain ongoing without material new developments.
Security News and Context
- Google releases Chrome update for actively exploited V8 zero-day; update Chrome and Chromium-based browsers immediately.
- Phishing campaign uses invisible Unicode characters to evade filters. Review email detections for obfuscated financial lures and reinforce reporting procedures.
- PostgreSQL fixes logical-decoding flaw enabling replication-role code execution. Review replication-role assignments and update supported PostgreSQL versions.
Recommended Actions
- Deploy Chrome/Chromium updates addressing actively exploited
CVE-2026-85046. - Identify and isolate exposed PowerJob workers; assess
CVE-2026-75430andCVE-2026-75431. - Patch SonicWall NSM, ASUS Control Center and Nango; restrict management interfaces immediately.
- Investigate German and European environments for TerminalFix indicators, ransomware staging and suspicious remote-terminal activity.
- Validate HAProxy and Linux system-binary integrity where relevant to the Ted backdoor campaign.
- Review PostgreSQL replication-role assignments and apply current updates.
- Continue remediation of previously reported items: SharePoint, Citrix NetScaler, PaperCut, Gitea, Langflow, SonicWall SMA1000, ownCloud, GitLab, SQL Server and Linux Kernel vulnerabilities.