GOOGLE has issued security updates for Chrome after confirming active exploitation of a V8 type-confusion bug tracked as CVE-2026-85046, patched in the latest stable release. The fix is part of a broader set of patches addressing multiple Chrome zero-days disclosed this year. The update underscores that exploitation is taking place in the wild, and Google notes that several actively exploited Chrome vulnerabilities have been resolved since the start of 2026.
In other top items, CERT Polska warned that MikroTik RouterOS users are being targeted via a chained set of zero-days (MikroTik’s MikroTrick) enabling unauthenticated remote takeover when remote SSH is enabled. Affected versions include fixes in 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
Separately, attackers are compromising unpatched Magento and Adobe Commerce storefronts with a zero-day named StyleSmuggler to inject a backdoor, enabling remote code execution and data exfiltration via a Rust-based C2. Other notable developments include a Coder registry compromise delivering credential-stealing modules, and the continuing risk from AI and edge-device threats, including observed prioritisation of vendor ecosystems over individual CVEs.
The week also highlights a growing trend of pre-authentication exposure and sophisticated social-engineering and supply-chain techniques, with advice to maintain patching alongside rigorous logging for post-incident investigation.