What you need to know today.
Actively exploited Chrome zero-day added to KEV, alongside critical flaws in Tenda, Mikrotik, libxml2, and WordPress plugins.

Google Chrome is facing a critical zero-day vulnerability, CVE-2026-85046, which has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. This type confusion flaw in the V8 JavaScript engine allows remote attackers to execute arbitrary code within the browser's sandbox through a crafted HTML page. The vulnerability, rated High by Chromium security, underscores the ongoing threats to web browser security and the importance of timely patching. Google has released an update to version 152.0.7977.82 to address this exploit, as reported by Help Net Security.
Multiple critical vulnerabilities have been disclosed in Tenda devices, primarily affecting the CP3 and HG10 models. CVE-2026-86152 and CVE-2026-86151, found in Tenda CP3, allow for OS command injection due to flaws in the Kylin component and Network Configuration Management, respectively. Similarly, CVE-2026-86167 in Tenda HG10 also permits OS command injection via the Boa web server's gponConf function. Additionally, CVE-2026-86165 in the HG10 model presents a buffer overflow risk through the formURL function. These Tenda vulnerabilities, with CVSS scores up to 10.0, highlight significant security weaknesses in these network devices.
Mikrotik RouterOS is affected by several critical and high-severity vulnerabilities. CVE-2026-86060 and CVE-2026-67276, both rated Critical, involve privilege escalation through argument handling flaws in SSH login and incomplete RSA public key verification, respectively. Furthermore, CVE-2026-67281 (High) permits unauthenticated file reads via the WebFig interface, and CVE-2026-67277 (High) allows unauthenticated UDP tests by exploiting a race condition in the btest connection handling. These issues collectively expose Mikrotik devices to significant risks of unauthorized access and control.
Critical vulnerabilities have been identified in libxml2, a widely used XML parsing library. CVE-2025-49796 and CVE-2025-49794, both rated Critical with a CVSS score of 9.1, involve memory corruption and use-after-free issues, respectively. These flaws can be triggered by processing specially crafted XML files, potentially leading to application crashes or arbitrary code execution. These vulnerabilities were also noted in CISA ICS Advisories for Siemens SINEC OS and Ruggedcom Rox, indicating potential impact on industrial control systems.
Several WordPress plugins are also subject to vulnerabilities this window. The SEO Flow by LupsOnline plugin (before 3.0.3) has CVE-2026-78362, an authentication bypass flaw allowing unauthenticated users to access administrator settings. The SureCart plugin (before 4.6.3) suffers from CVE-2026-18480, enabling subscriber-level users to alter other users' email addresses. Lastly, the RegistrationMagic plugin (before 6.0.9.9) has CVE-2026-77826, which allows unauthenticated attackers to log in as existing users by exploiting improper Facebook access token validation.