Weekly Recap: Chrome 0-Day Exploited, N-Central RCE Flaws, Supply Chain Hit
Google has shipped an emergency patch for a high-severity Chrome vulnerability tracked as CVE-2026-85046 (CVSS 8.8), a type confusion bug in the V8 JavaScript and WebAssembly engine that is already being exploited in the wild. Discovered and reported by researcher Salvatore Gulizia (aka Serotav) on August 4, 2026, the flaw allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. The fix is included in Chrome 152.0.7977.82, and users should update immediately or run a browser fingerprint test to confirm their browser version and exposure surface.
N-able has issued hotfixes for three severe N-central flaws: CVE-2026-86206 and CVE-2026-86207, which permit authentication bypass and full platform takeover, and CVE-2026-86218, a maximum-severity pre-authenticated remote code execution bug scoring a 10.0 on the CVSS scale. Huntress reports active exploitation of one of the authentication-bypass vulnerabilities after investigating the September 4 compromise of a fully patched customer environment. Security teams should also audit exposed management interfaces with a port scanner to ensure N-central consoles are not internet-reachable and confirm that log retention is sufficient for forensic analysis.
Beyond these two headline issues, attackers have been spotted weaponizing a text-based QR code in phishing emails that still renders even when images are blocked, neutralizing a common user-side defense. A trusted code repository also delivered a malicious package capable of harvesting developer credentials, underscoring once again why software supply chain integrity is now a frontline concern. Network operators should hunt for signs of router hijacking and DNS tampering by running a DNS leak test on edge devices and reviewing WHOIS history for unauthorized registrar changes. With active campaigns targeting browsers, managed service platforms, routers, and e-commerce backends, defenders cannot afford to rely solely on patch cadence, and continuous validation of credentials, certificates, and exposed services remains essential to staying ahead of the threat actors.