Chrome Zero-Day CVE-2026-2441 Exploited in the Wild
Google patches CVE-2026-2441, a high-severity use-after-free in Chrome actively exploited in the wild. This is Chrome first zero-day of 2026. Update immediately.
Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.
Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.
Updated August 9, 2026 — 178 published advisories, with new analysis most weekdays. Recent coverage includes a CVSS 10.0 Metabase zero-day already being exploited to steal every stored database credential, a maximum-severity Adobe Campaign Classic bug that lets an unauthenticated attacker run code with no user interaction (CVE-2026-48449), an OpenWrt DHCPv6 flaw that hands an unauthenticated attacker root on the router itself (CVE-2026-53921), a critical cPanel and WHM flaw that lets any paying hosting customer run SQL as database root (CVE-2026-58048), and an Azure Cosmos DB flaw that exposed a platform-wide master key (CVE-2026-66803). If one of these touches a system you run and you are not sure what to do next, our 24/7 staffed security operations center handles the triage for you.
Google patches CVE-2026-2441, a high-severity use-after-free in Chrome actively exploited in the wild. This is Chrome first zero-day of 2026. Update immediately.
Russia's APT28 began exploiting Microsoft Office CVE-2026-21509 just 72 hours after disclosure, targeting Ukraine, Slovakia, and Romania with email-stealing malware and Covenant implants.
Read moreA high-severity Microsoft Office zero-day (CVE-2026-21509) is being actively exploited to bypass security controls designed to block risky COM and OLE content. Successful exploitation requires a user to open a malicious Office document, enabling follow-on payload execution and intrusion activity. Apply Microsoft's out-of-band update immediately or deploy the recommended registry-based mitigation if patching is delayed.
Read moreReact2Shell refers to a newly disclosed set of exploitation paths affecting React Server Components and modern server-side rendering workflows. In vulnerable implementations, attackers may escalate from user-driven application behavior into sensitive server-side execution, data access, or compromise of backend services. Organizations using RSC or SSR patterns should audit server-executed components, reduce dynamic execution paths, and apply strict validation and least-privilege controls.
Read moreOur CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.
Subscribe to our newsletter and get the latest security insights delivered to your inbox.