Sunday, September 13, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Google Chrome accounts for the largest share of the critical disclosures from Saturday, with at least eight CVSS 9.6 vulnerabilities in the browser alongside a CVSS 9.9 flaw in the Masteriyo LMS WordPress plugin and a CVSS 9.8 flaw in the DS Ad Rotator WordPress plugin. Critical CVEs fell to 19 (down 32% from 28 the prior day) while high-priority CVEs rose to 86 (up 76% from 49). Notable entries include CVE-2026-82845 (Masteriyo LMS, CVSS 9.9), CVE-2026-81402 (DS Ad Rotator, CVSS 9.8), and the Chrome cluster led by CVE-2026-87494 and CVE-2026-87504 (both CVSS 9.6). Browser memory-safety bugs and WordPress plugin access-control flaws dominate the critical set, with 14 actively exploited vulnerabilities spanning network edge appliances (Citrix NetScaler, Fortinet, Cisco FMC, MikroTik RouterOS), remote management tools (N-able N-central, ConnectWise ScreenConnect), and developer platforms (GitLab, JFrog Artifactory). Prioritize Chrome updates across managed endpoints, audit WordPress sites for the two affected plugins, and confirm fix status for each edge and remote-management product in the vendor advisory before restricting internet-facing management interfaces.

  • Google Chrome leads the day with at least eight CVSS 9.6 critical vulnerabilities, the largest single-vendor cluster in the brief
  • 19 critical CVEs, down 32% from 28 the prior day
  • 86 high-priority CVEs, up 76% from 49 the prior day
  • WordPress plugin flaws in Masteriyo LMS (CVE-2026-82845, CVSS 9.9) and DS Ad Rotator (CVE-2026-81402, CVSS 9.8) allow high-impact compromise of affected sites
  • Check first: Chrome on managed endpoints, WordPress sites running Masteriyo LMS or DS Ad Rotator, and internet-facing Citrix NetScaler, Fortinet, Cisco FMC, and MikroTik devices
  • 14 actively exploited CVEs include GitLab (CVE-2026-85706, CVSS 10), Microsoft Windows, ConnectWise ScreenConnect, and JFrog Artifactory

Immediate action: Update Google Chrome across all managed endpoints and audit WordPress installations for the Masteriyo LMS and DS Ad Rotator plugins, then review internet-facing Citrix NetScaler, Fortinet, Cisco FMC, MikroTik, N-able, ConnectWise, GitLab, and JFrog systems given confirmed active exploitation. Confirm fix status for each product in the vendor's advisory and restrict exposed management interfaces where an update cannot be applied immediately.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation