Google fixes the fifth actively exploited Chrome zero-day of 2026

2026-06-09T14:51:48Zd07dd2d916ec2cf568e76c7909cc138ec23a47fb05964da79885ccc280de4829
account-takeoveradmin-account-takeoverai-recovery-toolberriaicheck-pointchromecisaeverest-forms-proexploit-in-the-wildinstagramiot-botnet','c0xmo','gafgyt','ddos','cve-2021-27137','data-breacknown-exploited-vulnerabilitieslinux-kernellitellmlocal-privilege-escalationmetanf_tablesnsophysical-intrusionunc3753v8vishingwhatsappwordpresszero-day

What happened

Multiple high-priority incidents and disclosures: Google released an emergency patch for a V8 Chrome zero-day actively exploited in the wild (CVE-2026-11645). CISA added new entries to its Known Exploited Vulnerabilities catalog including BerriAI LiteLLM/Check Point issues (one listed as CVE-2026-42271). A Linux kernel nf_tables use‑after‑free (CVE-2026-23111) enables local privilege escalation to root. Everest Forms Pro for WordPress had a PHP injection vulnerability (CVE-2026-3300) allowing attackers to create rogue admin accounts. The UNC3753 group escalated operations from vishing to on‑s­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d07dd2d916ec2cf568e76c7909cc138ec23a47fb05964da79885ccc280de4829
Enrichment time
2026-06-09T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Google fixes the fifth actively exploited Chrome zero-day of 2026 · Baitaphish