Friday, September 11, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Six Google Chrome flaws rated CVSS 9.6 and a CVSS 9.8 remote code execution issue in Apache ActiveMQ Artemis (CVE-2026-57967) lead yesterday's disclosures, alongside CVE-2026-8778 (CVSS 9.8) in the MIPL Grouped Checkout Fields plugin for WooCommerce. The day brought 57 critical CVEs (up from 11) and 93 high-priority CVEs (up from 30), for 150 total. Other notable entries include CVE-2026-88869 (CVSS 9.3) in WWBN AVideo and CVE-2026-78082 (CVSS 9.3) in the JoomShaper SP Property extension for Joomla. Eleven CVEs have confirmed active exploitation, spanning Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center, Mikrotik RouterOS, Adobe Commerce, N-able N-central, Microsoft Windows and Chrome, which puts internet-facing edge and management appliances in the highest-exposure group. Prioritise browser fleet updates and restrict administrative access to edge gateways and firewall management consoles to trusted networks while you verify fix status with each vendor.

  • Six Google Chrome CVEs at CVSS 9.6 (CVE-2026-87448, CVE-2026-87455, CVE-2026-87464, CVE-2026-87474, CVE-2026-87488, CVE-2026-87512) make browser updates the widest-reaching item of the day
  • 57 critical CVEs (CVSS 9.0+), up 418% from 11 the previous day
  • 93 high-priority CVEs (CVSS 7.0-8.9), up 210% from 30 the previous day
  • Remote code execution dominates the critical set: CVE-2026-57967 (CVSS 9.8) in Apache ActiveMQ Artemis and CVE-2026-8778 (CVSS 9.8) in a WooCommerce checkout plugin are both unauthenticated-reachable message broker and web application paths
  • Check first: Chrome and Chromium-based browsers, Apache ActiveMQ Artemis brokers, Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center, Mikrotik RouterOS, and WordPress or Joomla sites running the affected plugins
  • 11 CVEs are confirmed exploited in the wild, including Adobe Commerce (CVE-2026-75650), N-able N-central (CVE-2026-86218), and two Mikrotik RouterOS issues

Immediate action: Patch the actively exploited set first: Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center, Mikrotik RouterOS, Adobe Commerce, N-able N-central, Microsoft Windows, and Google Chrome, since those are internet-facing or centrally trusted systems already under attack. Then update browser fleets for the six CVSS 9.6 Chrome issues and review Apache ActiveMQ Artemis brokers, WooCommerce checkout plugins, and Joomla SP Property installations. Confirm the fixed version and any interim mitigations in each vendor's own advisory before closing out the work.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation