VYPR
AI Brief2026-09-22· generated Sep 21, 2026

What you need to know today.

Actively Exploited Flaws Hit Chrome, Linux Kernel, and SonicWall; Numerous Critical Vulns Disclosed.

A critical vulnerability in Google Chrome's V8 JavaScript engine, CVE-2026-87491, has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. This out-of-bounds write flaw allows remote attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious HTML page. The vulnerability was patched in Chrome version 153.0.8010.36, and reports indicate it has been chained with Windows zero-day exploits by sophisticated threat actors, including those linked to Chinese espionage groups, to deploy malware like the GRIMWEDGE backdoor. This marks the seventh zero-day exploited in Chrome this year, underscoring the urgency for users to update their browsers.

SonicWall's SMA1000 Appliance Management Console (AMC) is facing active exploitation due to a post-authentication OS command injection vulnerability, CVE-2026-83549. This flaw allows authenticated attackers to execute arbitrary commands on the underlying operating system, potentially leading to full system compromise. The vulnerability has been added to the CISA KEV catalog, and multiple threat actors have been observed chaining it with other vulnerabilities to gain initial access and deploy reverse shells or crypto miners. Rapid7 has noted that this vulnerability, along with CVE-2026-83548, can be exploited to achieve unauthenticated remote code execution. Organizations using the affected SMA1000 series appliances are urged to apply patches immediately.

The Linux kernel is affected by CVE-2025-39682, a vulnerability related to the handling of zero-length TLS records on the receive list. This flaw could potentially lead to denial-of-service conditions or other unspecified impacts. CISA has added this vulnerability, along with two others, to its KEV catalog, citing active exploitation in the wild. While details on the exact impact and exploitation methods are scarce, the inclusion in the KEV catalog highlights its significance. Users are advised to update their Linux kernel to a patched version as soon as possible.

A wave of critical vulnerabilities has been disclosed across several consumer-grade networking devices, including Netcore NBR200V2, D-Link DIR-868L, Comfast CF-N1-S, and Totolink A3002MU. These flaws, primarily buffer overflows and command injection vulnerabilities, carry a CVSS score of 10.0 and affect components such as CGI endpoints, authentication handlers, web management interfaces, and wireless security configurations. While specific exploitation details are limited, the high severity and widespread nature of these devices suggest a significant potential attack surface for unauthenticated remote code execution and device compromise. Users of these devices should check for firmware updates.

IBM MQ Appliance and IBM Common Licensing Agent are impacted by critical vulnerabilities. CVE-2026-10747 in IBM MQ Appliance allows unauthenticated remote attackers to cause a denial of service or potentially execute arbitrary code via heap buffer overflows during protocol message processing. Separately, CVE-2025-15399 in the IBM Common Licensing Agent is a cross-site request forgery (CSRF) vulnerability that could allow attackers to execute malicious actions by tricking users into clicking a crafted link. Both vulnerabilities pose significant risks, and users should consult IBM's security advisories for patching information.

WordPress sites are facing multiple threats, with critical vulnerabilities found in the Web to Print Online Designer plugin (before 2.15.0) and the Botiga Pro plugin (before 1.6.5). The Web to Print plugin suffers from an arbitrary file upload vulnerability allowing unauthenticated attackers to upload malicious files. Botiga Pro has a REST route vulnerability enabling unauthenticated users to alter WordPress options, potentially leading to privilege escalation. Additionally, the Gravity Forms plugin (up to 3.1.0.4) has an arbitrary file upload flaw. These vulnerabilities highlight the ongoing risks associated with WordPress plugins and the need for diligent patching and security practices.

Synthesized by Vypr AI