Google fixes the fifth actively exploited Chrome zero-day of 2026
2026-06-09T14:51:48Z•d07dd2d916ec2cf568e76c7909cc138ec23a47fb05964da79885ccc280de4829
account-takeoveradmin-account-takeoverai-recovery-toolberriaicheck-pointchromecisaeverest-forms-proexploit-in-the-wildinstagramiot-botnet','c0xmo','gafgyt','ddos','cve-2021-27137','data-breacknown-exploited-vulnerabilitieslinux-kernellitellmlocal-privilege-escalationmetanf_tablesnsophysical-intrusionunc3753v8vishingwhatsappwordpresszero-day
What happened
Multiple high-priority incidents and disclosures: Google released an emergency patch for a V8 Chrome zero-day actively exploited in the wild (CVE-2026-11645). CISA added new entries to its Known Exploited Vulnerabilities catalog including BerriAI LiteLLM/Check Point issues (one listed as CVE-2026-42271). A Linux kernel nf_tables use‑after‑free (CVE-2026-23111) enables local privilege escalation to root. Everest Forms Pro for WordPress had a PHP injection vulnerability (CVE-2026-3300) allowing attackers to create rogue admin accounts. The UNC3753 group escalated operations from vishing to on‑s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d07dd2d916ec2cf568e76c7909cc138ec23a47fb05964da79885ccc280de4829
- Enrichment time
- 2026-06-09T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.