ZeroHour
Vendor

Proofpoint

17 mentions in 7 days · 24 in 30 days · 25 total · first seen · last

Timeline

Attackers are weaponizing the gap between Chromium fixes and Chrome patches

Espionage actors use the BlueMoon exploit kit to chain Chrome V8 and Windows kernel zero-days via spear phishing, gaining full admin on unpatched endpoints.

Proofpoint, working with Google Threat Intelligence Group, Microsoft Threat Intelligence Center and Volexity, reports that the BlueMoon exploit kit chains V8 type confusion CVE-2026-85046, V8 sandbox escape CVE-2026-87491 and Windows kernel LPE CVE-2026-85880, all rated high severity. The V8 flaws were fixed in upstream Chromium source but had not yet reached Chrome stable releases, creating a patch gap that attackers reverse-engineered and weaponized. A China-aligned state-sponsored actor used the kit from August 28 against a small number of US NGOs, mining and commodity trading firms via rapport-building spear phishing, and within days several mostly China-linked espionage clusters adopted BlueMoon. The chain yields full Windows admin privileges from a single phishing click; defenders should patch Chrome and Windows, apply Proofpoint detections and hunt for leftover artifacts.

CSO Onlineupdated · 11h agofirst · 4d agoExploit / PoC in the wild 20 sourcesCVE-2026-85046CVE-2026-87491CVE-2026-85880

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

Proofpoint documents BlueMoon exploit kit used by four espionage groups to chain Chrome V8 and Windows flaws via phishing, all now in CISA's KEV.

Proofpoint identified a shared Chrome and Windows exploit kit, BlueMoon, used by four espionage groups against Chrome on Windows within days of one another. Attacks began with phishing emails leading to web pages that exploited two Chrome V8 vulnerabilities, followed by a Windows flaw to escape browser protections and gain higher privileges. The Chrome flaws were patched in Stable on September 3 and 8, 2026, the Windows flaw was fixed in September Patch Tuesday, and all three were actively exploited and added to CISA's KEV catalog. Researchers found clues, but no conclusive evidence, that the kit was developed with AI assistance.

Malwarebytes Labsupdated · 11h agofirst · 5d agoExploit / PoC in the wild 20 sources1

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Multiple China-linked espionage groups share the BlueMoon exploit kit chaining Chrome V8 zero-days and a Windows ALPC LPE to deploy backdoors.

Proofpoint and Volexity report that multiple espionage clusters share the BlueMoon exploit kit, chaining Chrome V8 zero-days CVE-2026-85046 and CVE-2026-87491 with the Windows ALPC local privilege escalation CVE-2026-85880. Proofpoint observed spearphishing use since August 28 by JungleBamboo (APT31), while Volexity saw UTA0560 targeting NGOs from September 1; UNK_LateNight hit US aerospace/defense with ShadowPad and UNK_DoubleCheck targeted Vietnamese manufacturers. The kit's maintainers reverse-engineer public Chromium fixes before stable Chrome releases, and Proofpoint suspects the ALPC exploit has existed since 2025.

BleepingComputerupdated · 11h agofirst · 5d agoExploit / PoC in the wild 20 sourcesCVE-2026-85046CVE-2026-87491CVE-2026-858801

Proofpoint Expands AI-Powered Investigations to Microsoft 365 and Deepens Insider Risk Visibility into AI Activity

Proofpoint expands AI-powered investigations into Microsoft 365 and adds AI interaction visibility to insider risk investigations.

Proofpoint announced that Prism Investigator will connect directly to Microsoft 365 email, Teams, and files without requiring archived content, expected in Q4 2026. Human Communications Intelligence agents will incorporate AI communications governance signals, capturing interactions with copilots and AI agents, into Insider Threat Management. The vendor positions these as part of a unified platform for data security, insider risk, and communications governance.

Proofpoint Threat Insight · 5d agoIndustry1

Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days

Proofpoint reports four nation-state actors, mostly China-nexus, adopted the BlueMoon Chrome and Windows zero-day exploit kit within 12 days, targeting US organizations.

Proofpoint tracked an exploit kit dubbed BlueMoon that chains CVE-2026-85046, a Chrome V8 type-confusion bug, with an unnamed V8 sandbox escape and CVE-2026-85880, a Windows kernel privilege escalation using ALPC and the Windows Notification Facility. The first observed use was by China-nexus TA412 (APT31, Violet Typhoon, JungleBamboo) on August 28, 2026 against US NGOs, mining companies, and commodity trading firms, followed by UNK_LateNight targeting US aerospace and defense companies on September 2. Both V8 bugs were patch-gap zero-days: the fix was committed to Chromium on August 7 but reached stable Chrome on September 3, enabling rapid weaponization from public patches. TA412's post-exploitation payload, GemStone, is a malicious browser extension posing as an AI-powered Google Gemini companion that captures keystrokes, cookies, screenshots, and browsing history via a Cloudflare Worker C2.

Security Affairsupdated · 11h agofirst · 5d agoExploit / PoC in the wild 20 sourcesCVE-2026-85046CVE-2026-858801

China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks

China-linked clusters deploy the BlueMoon kit chaining Chrome V8 CVE-2026-85046 and Windows LPE CVE-2026-85880 in espionage campaigns.

Proofpoint researchers identified BlueMoon, an exploit kit combining a V8 type-confusion RCE (CVE-2026-85046), a V8 sandbox escape, and a Windows kernel privilege-escalation flaw (CVE-2026-85880), first observed August 28, 2026. At least four clusters adopted it, led by TA412 (also tracked as APT31/Violet Typhoon) and followed by UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, targeting aerospace, manufacturing, government, consulting, and financial sectors. The kit exploited a nearly four-week patch gap between the public Chromium commit (August 7) and stable rollout (September 3). TA412 delivered the GemStone Chrome extension masquerading as a Gemini companion, while other clusters deployed ShadowPad via DLL sideloading, a Rust loader, and DoH-based C2.

GBHackersupdated · 11h agofirst · 5d agoExploit / PoC in the wild 20 sourcesCVE-2026-85046CVE-2026-858801

AI adoption brings new security headaches for already stretched CISOs

Proofpoint's 2026 Voice of the CISO report finds 79% of CISOs must manage AI-related risks without added resources or expertise.

Proofpoint's 2026 Voice of the CISO report says AI governance is expanding CISO responsibilities faster than resources, with 79% expected to manage AI-related risks without proportional support. Seventy-eight percent of CISOs consider GenAI a security risk, chiefly customer data loss through public AI platforms, and 61% expect a targeted attack within 12 months, down from 76% in 2025. Human risk remains the top vulnerability for 79% of respondents, and 93% of organizations with material data loss said departing employees played a role. Cloud account takeover now tops perceived threats, while email fraud, ransomware and malware declined in the rankings.

Help Net Security · 5d agoIndustry

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits

Proofpoint reports the BlueMoon exploit kit, chaining two Chrome V8 zero-days and a Windows ALPC bug, being shared across China-linked espionage groups.

Proofpoint identified a new exploit kit, BlueMoon, first observed on August 28 and used by TA412 (APT31/Violet Typhoon) against US NGOs, mining firms, and commodity trading companies. The kit chains a V8 type confusion RCE (CVE-2026-85046), a V8 sandbox escape, and a Windows Advanced Local Procedure Call privilege escalation (CVE-2026-85880), both patched flaws having been exploited in the wild. At least four espionage groups, most with suspected China nexus including UNK_LateNight, adopted the kit within days, targeting US aerospace firms with defense-sector lures. Fewer than 20 organizations were observed targeted, and researchers believe AI-assisted exploit development against upstream Chromium patches enabled the kit's rapid creation and sharing.

The Register · Securityupdated · 11h agofirst · 5d agoExploit / PoC in the wild 20 sourcesCVE-2026-85046CVE-2026-858801

Four groups caught using the same Chrome and Windows exploit kit

Proofpoint reports at least four hacking groups, some China-linked, share the BlueMoon exploit kit chaining Chromium and Windows kernel vulnerabilities to install malware.

Proofpoint named the nearly identical kit BlueMoon; it chains two Chromium vulnerabilities with one Windows kernel privilege-escalation flaw affecting Windows 10 (October 2018 Update and 2004), Windows Server 2019 and 2022, and the initial Windows 11 release. All three vulnerabilities received patches within 24 hours of the activity. The kit is being actively used by at least four hacking groups, some with Chinese government ties. Proofpoint links the rapid, visible sharing of a historically rare full browser exploit chain to the Chromium supply-chain patch gap and AI-assisted exploit development.

Proofpoint Threat Insightupdated · 11h agofirst · 6d agoExploit / PoC in the wild 20 sources1

CISOs are feeling the security burden of accelerated AI use

Proofpoint's Voice of the CISO survey finds 85% of CISOs prioritizing AI security, with 80% managing AI risks without proportional resources.

Proofpoint's annual Voice of the CISO report, a Censuswide survey of 1,600 CISOs across 16 countries, found 85% rank securing AI assistants, copilots and automation among top priorities for the next two years. Eight in ten say they must manage AI-related security risk without a proportional increase in resources or expertise, and 78% now consider generative AI a major security risk, up 18% year over year. Board alignment improved to 85%, though nearly 80% still report excessive board pressure; 80% cite human behavior as the biggest cyber vulnerability.

Proofpoint Threat Insight · 6d agoIndustry

Chinese espionage groups swarm to exploit triple-link chain of zero-days

At least four China-aligned espionage groups chained three zero-days in Chromium browsers and Windows ALPC for espionage since late August.

Proofpoint observed at least four state-aligned threat groups, starting with TA412/Violet Typhoon/APT31 on August 28, chaining three zero-days in the 'BlueMoon' exploit chain targeting Chrome, Chromium-based browsers and Microsoft Windows. The chain includes RCE flaws in Chromium's JavaScript engine (CVE-2026-85046, CVE-2026-87491) and a Windows Advanced Local Procedure Call privilege-escalation zero-day (CVE-2026-85880), enabling sandbox code execution, sandbox escape and system privileges. APT31 delivered the chain via phishing links to NGOs, mining and commodity trading firms in the US, installing a browser extension disguised as Google Gemini to surveil activity and steal credentials. Other groups (UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket) targeted US aerospace, Vietnamese manufacturing, and Indonesian and Singaporean organizations; fewer than 20 victims were directly observed but the true count is likely higher.

CyberScoopupdated · 11h agofirst · 6d agoExploit / PoC in the wild 20 sourcesCVE-2026-85046CVE-2026-87491CVE-2026-858802· 1 read

Chinese espionage groups swarm to exploit triple-link chain of zero-days

Four China-aligned espionage groups, starting with TA412/APT31, chained zero-days CVE-2026-85046, CVE-2026-87491 and CVE-2026-85880 to spy on targets since late August.

TA412 (Violet Typhoon/APT31) began exploiting the BlueMoon chain on Aug. 28, followed by UNK_LateNight (US aerospace, Sept. 2), UNK_DoubleCheck (Vietnamese manufacturing via a compromised Southeast Asian government account) and UNK_QuietRacket (Indonesia and Singapore government, consulting and finance, Sept. 3). The chain pairs Chromium JavaScript engine RCE flaws CVE-2026-85046 and CVE-2026-87491 with the Windows ALPC privilege-escalation zero-day CVE-2026-85880, enabling sandbox escape and system privileges. Delivery used phishing links installing a fake Google Gemini browser extension that surveilled browser activity and stole credentials; Proofpoint directly observed fewer than 20 organizations but expects wider proliferation as the kit spreads.

Proofpoint Threat Insightupdated · 11h agofirst · 6d agoThreat actor in the wild 20 sourcesCVE-2026-85046CVE-2026-87491CVE-2026-858801

4 groups caught using the same Chrome and Windows exploit kit

Proofpoint says at least four groups, some China-linked, actively share the BlueMoon kit chaining two Chromium and one Windows kernel exploit.

Proofpoint researchers report that at least four hacking groups, some with ties to the Chinese government, are actively using a nearly identical exploit kit named BlueMoon. The kit chains two Chromium browser vulnerabilities and one Windows kernel flaw affecting Windows 10, Windows 11 initial release, and a later Windows version to install malware of the attacker's choice. All three vulnerabilities received patches within the past 24 hours. Proofpoint attributes the kit's rapid, widely shared deployment to a Chromium patch-gap window and AI agents accelerating exploit development against publicly accessible upstream patches.

Ars Technica · Securityupdated · 11h agofirst · 6d agoExploit / PoC in the wild 20 sources

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Proofpoint links four espionage clusters, including China's APT31, using shared exploit kit BlueMoon chaining Chrome V8 and Windows ALPC zero-days.

Proofpoint reports a previously undocumented exploit kit, BlueMoon, chains Chrome V8 type confusion CVE-2026-85046 with an unassigned V8 sandbox escape and Windows ALPC heap overflow CVE-2026-85880 to achieve code execution and local privilege escalation. APT31 first used it on August 28, 2026 against US NGOs, mining, and commodity trading firms, deploying the GemStone browser backdoor disguised as a Google Gemini extension via the GhostChrome-X integrity bypass. UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket followed on September 2-3, targeting US aerospace, Vietnamese manufacturing, and Indonesian/Singaporean sectors with ShadowPad and sideloaded Rust and .NET payloads. Both V8 flaws were patch-gap zero-days, and verbose code suggests possible AI-assisted development.

The Hacker Newsupdated · 11h agofirst · 6d agoThreat actor in the wild 20 sourcesCVE-2026-85046CVE-2026-858801

Multiple Chinese hacking groups seen using identical Chrome zero-day exploit

Four China-linked espionage groups share identical BlueMoon Chrome zero-day exploit kit targeting US defense contractors and Asian government agencies.

Proofpoint identified at least four Chinese-aligned espionage groups (TA412/RedBravo, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket) using an identical Chrome zero-day exploit kit dubbed BlueMoon in late August through this week. Targets include US defense contractors, NGOs, mining companies, and Southeast Asian government agencies. The exploit chains a Chromium patch-gap vulnerability with a Windows flaw, delivering malware such as ShadowPad and a fake Gemini browser extension backdoor, with possible AI-assisted exploit development.

The Recordupdated · 11h agofirst · 6d agoExploit / PoC in the wild 20 sources1

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

Microsoft's September 2026 Patch Tuesday delivers a record patch count, fixing two exploited zero-days and a wormable DNS flaw dubbed a SigRed successor.

Microsoft's September 2026 Patch Tuesday sets another record patch count, fixing two vulnerabilities exploited as zero-days: CVE-2026-81963, a Windows Update Stack low-privilege-to-SYSTEM escalation reported by MSTIC, and CVE-2026-85880, a Windows Advanced Local Procedure Call escalation reported by Proofpoint. Zero Day Initiative's Dustin Childs urges priority on a cluster of 20 potentially wormable bugs including DNS RCE CVE-2026-69730, described as a spiritual successor to SigRed, plus Kerberos authentication bypass CVE-2026-69676 that could give any authenticated domain user RCE on domain controllers, and Exchange RCE CVE-2026-55007 via a malicious Visio attachment. All Windows fixes are bundled in cumulative updates, and experts stress prioritizing exploitable, reachable flaws over raw patch counts.

Help Net Security · 6d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69730+4 CVEs

Proofpoint 2026 Voice of the CISO Report Finds Cyber Resilience Improving, While AI Expands the CISO Mandate

Proofpoint's 2026 survey of 1,600 CISOs finds improving cyber resilience, rising human risk, and expanding AI responsibilities without added resources.

Proofpoint released its 2026 Voice of the CISO report, a Censuswide-conducted survey of 1,600 CISOs across 16 countries fielded in May 2026. Expected material cyberattacks fell from 76% to 61% year over year and material data loss declined from 66% to 53%, but 79% of CISOs now identify human risk as their biggest vulnerability and GenAI security concerns jumped 18 points to 78%. The report also finds 79% of CISOs expect to manage AI-related risks without proportional resources, and 85% say boards are evaluating cyber risk through a commercial lens.

Proofpoint Threat Insight · 6d agoIndustry

Proofpoint SOC Analyst Agent Uses OpenAI Cyber Models

Proofpoint launched its SOC Analyst Agent in private preview, using OpenAI Daybreak models to automate security investigations with human-controlled remediation, GA expected end of Q3 2026.

The SOC Analyst Agent uses OpenAI Daybreak cyber models to enable natural-language investigations across Proofpoint alerts, logs, DLP events and user risk signals, and to automate recurring threat hunts, data security investigations and escalation reporting. It is currently in private preview with general availability expected by the end of Q3 2026, and it does not independently make account changes or take remediation actions. Proofpoint joined the OpenAI Daybreak Defense Network in June 2026 and is exploring additional uses for the models in threat research, data security and AI security workflows.

Proofpoint Threat Insight · 7d agoTools

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1

Proofpoint Strengthens Executive Leadership Team with Appointment of Chief Legal Officer and Chief People Officer

Proofpoint appointed Brian Levey as Chief Legal Officer and Puja Jaspal as Chief People Officer, strengthening its executive leadership team.

Proofpoint announced on September 8, 2026 the appointments of Brian Levey as Chief Legal Officer and Puja Jaspal as Chief People Officer. Levey previously served as Chief Business Affairs & Chief Legal Officer at Upwork and spent 13 years at eBay; Jaspal was Chief People Officer at Fastly with prior senior roles at Cisco, Visa, and Google. The hires support Proofpoint's stated expansion around human and AI-agent security.

Proofpoint Threat Insight · 7d agoIndustry

Proofpoint Brings OpenAI GPT Cyber Models into Security Operations to Help Defenders Investigate Threats Faster

Proofpoint launched its SOC Analyst Agent, an agentic investigation tool powered by OpenAI Daybreak models, now in private preview with Q3 GA planned.

Proofpoint introduced the SOC Analyst Agent, the first capability to emerge from its membership in the OpenAI Daybreak Defense Network, which it joined in June 2026. The agent converts natural-language questions into structured, traceable investigation findings across Proofpoint alerts, logs, DLP events and user risk signals, while leaving remediation decisions to human analysts. It is in private preview with select beta customers, and general availability is expected by the end of Q3 2026. Proofpoint cites its 2025 report finding that 54% of organizations already use AI-enhanced capabilities to triage and investigate alerts.

Proofpoint Threat Insight · 12d agoAI industry

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

NovaCookies AitM phishing kit, a Sneaky 2FA variant, uses genuine Docusign lures to steal Microsoft 365 sessions at hundreds of organizations.

Island disclosed NovaCookies, a $320/month adversary-in-the-middle phishing-as-a-service platform that relays Microsoft 365 sign-ins through attacker infrastructure to capture credentials, MFA codes, and authenticated sessions. Campaigns abuse genuine Docusign envelopes and Microsoft/Google redirect hops so each step looks legitimate, with lure domains on .vu and alternating-case labels such as PwPt-sHaRe. Proofpoint assesses NovaCookies as a Sneaky 2FA variant with added flows for Okta and Entra domains federated to GoDaddy, and a fully managed PhaaS model. It has targeted hundreds of organizations in the U.S., U.K., Canada, Germany, Israel, and the U.A.E., and is advertised via Telegram with anti-analysis checks like a Cloudflare gate.

The Hacker News · 14d agoPhishing & fraud

Locky Ransomware Installed Through Nuclear EK

Unit 42 reports Locky ransomware delivered through the Nuclear exploit kit using Flash exploits, adding a drive-by path to existing malspam distribution.

Unit 42 observed Locky ransomware being delivered by the Nuclear exploit kit in March 2016 via Flash exploits, following February reports of Neutrino EK distributing Locky. Infections follow a drive-by chain through a gate to the Nuclear EK, which either installs Locky directly or drops a downloader that retrieves it from another domain. Locky retains two distribution paths: malspam with malicious Office macros or JavaScript attachments and exploit kit traffic triggered by casual web browsing.

Palo Alto Unit 42 · 29d agoRansomware in the wild1

Decline in Rig Exploit Kit

Rig exploit kit activity dropped roughly 75% after the pseudo-Darkleech and EITest campaigns stopped using EKs, reflecting an overall decline in exploit kit activity.

Rig EK activity fell sharply in 2017: the pseudo-Darkleech campaign disappeared at the end of March, cutting Rig traffic about 50%, and the EITest campaign switched to tech support scams in late April, cutting another 50% in May. Broader causes include a shrinking browser target base, no major EK zero-day in over a year, and community takedowns of domain shadowing infrastructure. Criminals are shifting to malspam, social engineering schemes like fake HoeflerText notifications, and tech support scams.

Palo Alto Unit 42 · 29d agoExploit / PoC in the wild1

Cybercriminals Turn to Indirect Prompt Injection Attacks

Proofpoint reports cybercriminals are now adopting indirect prompt injection attacks against AI-powered systems.

Proofpoint's threat intelligence reports that cybercriminals have turned to indirect prompt injection attacks, extending the technique from a research concern into observed criminal tradecraft. The article is available by title only, so specific victims, campaigns, and targets are not detailed here.

Proofpoint Threat Insight · Aug 13, 2026AI safety & security in the wild

Related CVEs

  • Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation
    CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain.
    · Microsoft Windows 10 1607, 1809, 21H2, 22H2 · Microsoft Windows Server 2012, 2016, 2019, 2022 KEVmass
  • Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)
    Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references.
    · Google Chrome prior to 152.0.7977.82 · Google Chromium V8 V8 engine versions bundled with Chrome prior to 152.0.7977.82 KEV PoC ×5mass
  • Actively Exploited Out-of-Bounds Write in Google Chrome V8
    CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown.
    · Google Chrome (V8 JavaScript engine; tracked by CISA as 'Google Chromium V8') prior to 153.0.8010.36 KEVmass
  • Kerberos Capture-Replay Authentication Bypass in Microsoft Windows (RCE)
    CVE-2026-69676 is a capture-replay authentication bypass (CWE-294) in the Windows Kerberos implementation, disclosed by Microsoft as part of the September 2026 Patch Tuesday. An attacker who is already authorized (low-privilege credentials) can replay captured authentication material over the network to bypass authentication checks. Successful exploitation results in remote code execution, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.8). Any organization running Windows in an Active Directory environment is potentially affected, since Kerberos is the default authentication protocol for Windows domains. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a ~1.2% chance of exploitation within 30 days, though it shipped in a record-sized Patch Tuesday release alongside two actively exploited zero-days.
    · Microsoft Windows (Kerberos authentication implementation)mass
  • Use-After-Free Remote Code Execution in Microsoft Active Directory Domain Services
    CVE-2026-69524 is a use-after-free memory corruption flaw (CWE-416) in Microsoft's Active Directory Domain Services (AD DS), patched as part of Microsoft's September 2026 Patch Tuesday release. An unauthorized attacker with no privileges or user interaction can trigger the flaw remotely over the network, though the high attack-complexity rating suggests reliable exploitation may depend on favorable memory or timing conditions. A successful exploit yields remote code execution on the target, with high impact to confidentiality, integrity, and availability — typically a domain controller holding an organization's central authentication data. Any organization running Windows Server with the AD DS role enabled (i.e., operating domain controllers) is affected. As of this data there are no known in-the-wild exploits, no public proof of concept, and a modest 0.7% EPSS probability of exploitation within 30 days.
    · Microsoft Windows Server with Active Directory Domain Services (AD DS) rolemass
  • Double Free Enables Unauthenticated RCE in Microsoft Exchange Server
    CVE-2026-55007 is a double-free memory corruption flaw (CWE-415) in Microsoft Exchange Server in which the same heap allocation is freed twice, corrupting memory. A remote, unauthenticated attacker can trigger the flaw over the network, though the high attack complexity (AC:H) means reliable exploitation likely depends on favorable heap/timing conditions, making it harder to weaponize than typical pre-auth RCEs. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.1). Any organization running on-premises Microsoft Exchange Server is in scope, with the greatest risk on servers reachable from untrusted networks. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7% chance of exploitation within 30 days; it was disclosed amid Microsoft's record September 2026 Patch Tuesday (974 CVEs), which press coverage highlighted for notable Exchange flaws.
    · Microsoft Exchange Server (on-premises)mass
  • Missing-Authorization Local Privilege Escalation in Microsoft Data Sharing Service Client
    CVE-2026-73014 is a missing authorization flaw (CWE-862) in the Data Sharing Service Client, a Microsoft component assigned by the Microsoft CNA. A local attacker who already holds a low-privileged authorized account on the machine can invoke the service without a required authorization check and elevate privileges. Successful exploitation yields high impact to confidentiality, integrity, and availability (CVSS 7.8), which typically means gaining elevated rights on the local system. Any system running the affected component is exposed, though the attack requires local access and is not remotely exploitable. There is no known public proof-of-concept, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%; the fix shipped in Microsoft's September 2026 Patch Tuesday, which addressed 966 flaws.
    · Microsoft Data Sharing Service Clientmass
  • Unauthenticated out-of-bounds read DoS in Microsoft Windows BranchCache
    CVE-2026-69329 is an out-of-bounds read (CWE-125, arising from an integer-overflow condition, CWE-190) in the BranchCache component of Microsoft Windows. A remote, unauthenticated attacker can trigger the flaw over the network with no privileges or user interaction by sending malformed input to a system running BranchCache. Successful exploitation results only in denial of service of the BranchCache service — availability impact with no information disclosure or tampering (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Affected systems are Windows installations with the optional BranchCache feature enabled, such as branch-office caching deployments (Hosted Cache Servers or clients in distributed mode); the provided data does not specify affected version ranges. There is currently no known exploitation: the flaw was addressed in Microsoft's September 2026 Patch Tuesday (part of a 966-flaw release), has no public PoC, is not in CISA KEV, and carries an EPSS of 1.1% (62nd percentile).
    · Microsoft Windows BranchCache (component of Windows client and Windows Server)large
  • Use-After-Free Local Privilege Escalation in Microsoft Windows AVCTP Component
    CVE-2026-69401 is a use-after-free (CWE-416) in the Audio Video Control Transport Protocol (AVCTP) component of Microsoft Windows, the protocol layer used to control Bluetooth audio and video devices. A local, authorized (low-privileged) attacker can trigger the flaw by interacting with the vulnerable protocol handling such that memory is freed while still in use, though the high attack-complexity score indicates reliable triggering is non-trivial. Successful exploitation lets the attacker elevate privileges locally on the affected machine, with high impact to confidentiality, integrity, and availability once elevated. Any Windows system that includes the AVCTP/Bluetooth component is affected, meaning a very broad portion of the Windows installed base. Exploitation status is currently calm: there is no known public proof-of-concept, the flaw is not in CISA KEV, EPSS is low at 0.2%, and the fix shipped as part of Microsoft's September 2026 Patch Tuesday (966 flaws fixed, including 2 zero-days).
    · Microsoft Windows (Audio Video Control Transport Protocol / Bluetooth AVCTP component)mass
  • Unauthenticated DoS in Microsoft Active Directory Federation Services (AD FS)
    CVE-2026-72978 is an unauthenticated denial-of-service flaw in Microsoft Active Directory Federation Services (AD FS) caused by allocation of resources without limits or throttling (CWE-770). An attacker triggers it by sending network requests that cause the AD FS service to allocate resources without bound, exhausting capacity; the high attack-complexity score (AC:H) indicates the exhaustion condition is not reliably achieved on every attempt. A successful attack yields availability impact only (A:H) — the federation service can be knocked offline, interrupting sign-in/SSO for users who depend on it, with no confidentiality or integrity impact. Organizations running AD FS — typically enterprises using federated authentication with Microsoft 365/Entra ID on Windows Server — are affected. There is currently no evidence of exploitation (not in CISA KEV, no public PoC), EPSS puts the 30-day exploitation probability at 0.8%, and the fix shipped in Microsoft's September 2026 Patch Tuesday, which resolved 966 flaws including 2 zero-days.
    · Microsoft Active Directory Federation Services (AD FS)large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.