Chrome Zero-Day CVE-2026-2441 Exploited in the Wild
Google patches CVE-2026-2441, a high-severity use-after-free in Chrome actively exploited in the wild. This is Chrome first zero-day of 2026. Update immediately.
Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.
Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.
Updated September 12, 2026 — all 202 published advisories are browsable here. The newest one has already been used to break into 395 organizations: a pair of PaperCut print-management zero-days exploited in the wild, on the server that quietly sits inside the network and talks to every desktop in the building (CVE-2026-81578 and CVE-2026-82078). Behind it, a Cisco firewall management flaw under active attack and added to CISA's known-exploited list, on the console that controls the firewalls guarding the whole network (CVE-2026-20079), and a Chrome zero-day exploited in the wild, where simply visiting a booby-trapped site is enough to get code running on the machine (CVE-2026-87491). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.
Google patches CVE-2026-2441, a high-severity use-after-free in Chrome actively exploited in the wild. This is Chrome first zero-day of 2026. Update immediately.
Russia's APT28 began exploiting Microsoft Office CVE-2026-21509 just 72 hours after disclosure, targeting Ukraine, Slovakia, and Romania with email-stealing malware and Covenant implants.
Read moreA high-severity Microsoft Office zero-day (CVE-2026-21509) is being actively exploited to bypass security controls designed to block risky COM and OLE content. Successful exploitation requires a user to open a malicious Office document, enabling follow-on payload execution and intrusion activity. Apply Microsoft's out-of-band update immediately or deploy the recommended registry-based mitigation if patching is delayed.
Read moreReact2Shell refers to a newly disclosed set of exploitation paths affecting React Server Components and modern server-side rendering workflows. In vulnerable implementations, attackers may escalate from user-driven application behavior into sensitive server-side execution, data access, or compromise of backend services. Organizations using RSC or SSR patterns should audit server-executed components, reduce dynamic execution paths, and apply strict validation and least-privilege controls.
Read moreOur CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.
Subscribe to our newsletter and get the latest security insights delivered to your inbox.