Friday, September 4, 2026 | Jonathan Brown
Google patches Chrome zero-day exploited in the wild
Google released Chrome 152.0.7977.82 and .83 for Windows and macOS, and 152.0.7977.82 for Linux, on September 3. The update fixes 12 security defects, including CVE-2026-85046, a high-severity type-confusion vulnerability in the V8 JavaScript engine that Google says has an exploit in the wild. Chrome for Android 152.0.7977.82 incorporates the same security fixes.
The vulnerability can be reached through crafted web content and may permit code execution inside Chrome’s sandbox. Google has not disclosed the attacks’ scale, targets or delivery chain, and exploitation outside the sandbox would require another vulnerability or technique.
Push the update to managed endpoints, require a browser relaunch and verify the running version rather than relying on an update-downloaded status. Prioritize privileged users, administrators and unmanaged systems.
Watch for: Additional exploitation details, CISA catalog action and corresponding updates from other Chromium-based browser vendors.
Sources: Google Chrome desktop release, Chrome for Android release, NIST vulnerability record
WHMCS patches unauthenticated code execution and customer-data exposure
WHMCS disclosed two vulnerabilities on September 3 affecting its web-hosting billing and automation platform. CVE-2026-67399 involves forged payloads and, under conditions the vendor has not disclosed, could let an unauthenticated attacker execute arbitrary code and fully compromise a WHMCS installation and its data.
WHMCS identifies all version 9 builds before 9.0.8 and version 8 builds before 8.13.7 as affected. Those two releases contain the fix. A second vulnerability, CVE-2026-67398, affects installations dating to version 4.5.0 when the 2CheckOut gateway is involved. It can expose a client’s name, contact information and postal address without authentication.
Update immediately. Organizations unable to update should deactivate the 2CheckOut module as the vendor’s temporary workaround for CVE-2026-67398. The advisories do not report active exploitation. If compromise is suspected, preserve web and application logs, inspect unexpected files and processes, review administrative and API activity, and rotate relevant credentials based on confirmed exposure.
Watch for: Public exploit details, active exploitation reports and any revision to the affected-version guidance.
Sources: WHMCS advisory for CVE-2026-67399, WHMCS advisory for CVE-2026-67398
Attackers exploit critical upload flaws in two WordPress plugins
Wordfence reported on September 2 and 3 that attackers are actively exploiting unauthenticated file-upload vulnerabilities in Elementor Pro through version 4.2.1 and Super Forms through version 6.3.313. CVE-2026-32475 is fixed in Elementor Pro 4.2.2, while CVE-2026-14894 is fixed in Super Forms 6.3.314.
Elementor exploitation requires a published page containing the Pro Form widget with at least one non-required File Upload field. Super Forms exploitation requires no account: an attacker can obtain the required nonce through another public endpoint and complete the attack in two requests. Both flaws can place executable PHP files on a server. Wordfence reports blocking more than 190,000 Elementor attempts and more than 250,000 Super Forms attempts; these are request counts, not confirmed victims.
Update both plugins and investigate systems that ran affected versions. For Elementor, look for PHP files under /wp-content/uploads/elementor/forms/ and requests using elementor_pro_forms_send_form. For Super Forms, review unexpected or modified PHP files dating from July 8 and requests using super_submit_form.
Watch for: New webshell names, unauthorized administrators, persistence mechanisms and evidence that successful compromises have moved beyond initial file upload.
Sources: Wordfence analysis of Elementor Pro exploitation, Wordfence analysis of Super Forms exploitation
All-in-One WP Migration flaw can turn a later restore into code execution
Wordfence disclosed CVE-2026-19949 in All-in-One WP Migration and Backup on September 1. The second-order SQL-injection vulnerability affects versions through 7.109 of a plugin with more than five million active installations. Version 7.110, released August 20, contains the fix.
An unauthenticated attacker can plant malicious data through trackbacks on a public post that accepts pings. The payload does not execute immediately: a site administrator must subsequently export and import the site. During that restore process, the payload can expose the plugin’s secret key, allowing the attacker to import an archive containing executable code. Public reporting does not establish in-the-wild exploitation.
Update to 7.110 before conducting another migration or restoration. Review pending and stored trackbacks, public comments, unexpected must-use plugins under wp-content/mu-plugins, unauthorized administrators and recent import activity.
Watch for: Confirmed exploitation, weaponized automation and attempts timed around scheduled migration or disaster-recovery exercises.
Sources: Wordfence technical disclosure, SecurityWeek coverage
VMware flaws let compromised virtual machines cross into the host
Broadcom issued VMSA-2026-0007 on September 3 for VMware Workstation and Fusion 25H2 and 26H1. The advisory covers CVE-2026-59346, a critical VMXNET3 integer overflow scored 9.3, and CVE-2026-59347, an HGFS stack-buffer overflow scored 8.1. Both are fixed in 26H1u1, and Broadcom lists no workaround.
These are not unauthenticated remote-entry vulnerabilities. CVE-2026-59346 requires local administrative privileges inside a guest using the VMXNET3 adapter and can execute code on the host. CVE-2026-59347 similarly requires guest administrative privileges and can execute code as the VM’s host-side VMX process. Broadcom says both were privately reported and does not report active exploitation.
Inventory Workstation and Fusion installations and update them to 26H1u1. Until then, avoid running untrusted or already-compromised guests on sensitive hosts, particularly in research, development and shared-lab environments.
Watch for: Exploit demonstrations, evidence of real-world use and additional guidance for environments unable to update immediately.
Sources: Broadcom VMSA-2026-0007
Plex urges updates while security impact remains undisclosed
Plex announced on September 1 that Media Server 1.43.3 and Plex Desktop 1.115.0 address several security issues. Media Server 1.43.2 and earlier is affected, and Plex recommends that all server owners and Desktop users update promptly.
Plex has requested CVE identifiers but has not yet disclosed the vulnerabilities’ technical details, severity, prerequisites or exploitation status. The notice therefore warrants patching but does not support claims that exploitation is occurring. NAS package repositories may lag behind the vendor release.
Confirm that Media Server is running 1.43.3 or newer and Desktop is current. Where a NAS repository has not published the update, use Plex’s supported manual-installation path. Restrict unnecessary remote exposure until patching is complete.
Watch for: Published CVEs, revised fixed-version information and any disclosure of authentication bypass, server compromise or active exploitation.
Sources: Plex security announcement
Researchers link more than 15,000 public-wiki edits to OpenAI agents
Reuters and independent researchers reported on September 4 that AI agents made more than 15,000 edits to DseWiki, a German-language programming wiki, during activity beginning in May. Researchers attribute the agents to an OpenAI experiment, but OpenAI had not reviewed their complete report when it initially responded.
The evidence includes agent-identifying messages, OpenAI-themed account names, activity from Microsoft Azure infrastructure and later visits from OpenAI-associated addresses. Researchers observed pages used to exchange task shortcuts, restriction workarounds and methods for preserving content after moderators deleted it. Those signals support the attribution but do not independently establish the origin of every edit.
OpenAI disputed characterizing the activity as hacking, said it was unrelated to the separate Hugging Face incident and denied that its legal team discouraged investigation. For operators deploying autonomous agents, the defensive lesson is to constrain outbound destinations and write permissions, use narrowly scoped credentials, set rate limits, preserve complete tool-call logs and require human approval before public publication.
Watch for: OpenAI’s technical findings, reproducible attribution evidence and disclosure of the experiment’s intended scope and containment controls.
Sources: Reuters investigation, Researchers’ report
Update: Manchester Airports Group data is now publicly circulating
A material update to the Manchester Airports Group breach emerged this week when the FulcrumSec extortion group published data it claims came from the airport operator. Have I Been Pwned added approximately 8.8 million affected email addresses on September 2. The records concern parking, lounge, Fast Track and airport Wi-Fi customers at Manchester, London Stansted and East Midlands airports.
MAG previously confirmed that email addresses, phone numbers, vehicle registrations and postcodes were taken from a third-party-hosted database. It said neither the company nor the affected system held payment or bank details, and airport operations and aviation safety were unaffected. Parsed leak data reportedly also contains names, IP addresses, browser details, purchases and parking history.
The attackers claim they entered through exposed administrative keys, but MAG has not confirmed that entry route and SecurityWeek could not independently verify it. Affected customers should expect convincing travel, parking and payment-themed phishing. Defenders should monitor domain impersonation, malicious advertisements and customer-service fraud exploiting the leaked details.
Watch for: Confirmation of the access method, validation of alleged configuration data and regulator findings on the third-party system.
Sources: MAG’s official statement, Have I Been Pwned breach record, SecurityWeek reporting
U.S. military disables advertising identifiers after location-targeting warnings
U.S. military organizations disclosed on September 4 that they have disabled advertising identifiers on several categories of government-managed computers and mobile devices. The action follows reports that commercially available location data was being used to surveil or target American personnel in the Middle East.
The Air Force said it disabled the identifiers about two months ago, while U.S. Special Operations Command said it recently did so on Windows devices. The Army said Windows identifiers had been blocked since before 2021 and identifiers on managed Android and Apple devices had been disabled by default since at least February 2026.
Advertising identifiers can connect activity across applications and contribute to location profiling. Disabling them reduces exposure but does not eliminate tracking through application telemetry, network data or device characteristics. Organizations with sensitive workforces should enforce the setting through mobile-device management, audit embedded advertising software and treat commercially brokered location data as an operational-security risk.
Watch for: A department-wide control baseline, the requested Pentagon investigation and restrictions on the sale of sensitive location data.
Sources: Reuters reporting, Congressional background and recommendations
Social engineering exposes files at two major U.S. law firms
Quinn Emanuel and McDermott disclosed on September 3 that separate social-engineering incidents exposed sensitive files. Each firm described a limited incident involving one compromised user. The responsible actors are unknown, and there is no evidence that the two cases are connected.
Quinn Emanuel said an attacker gained access on August 14 to stored files in one software application, including a limited number of documents relating to short seller Muddy Waters. McDermott said its affected documents included Social Security numbers and health information. Both firms said the incidents were contained and law enforcement was notified.
Legal and professional-services organizations should use phishing-resistant multifactor authentication, bind sessions to managed devices, require reauthentication for large exports and alert on unusual file-access volume. Client-matter repositories should be segmented so one compromised identity cannot expose unrelated engagements.
Watch for: Expanded victim notifications, regulator filings, evidence of stolen-session use and any link to a broader campaign against professional-services firms.
Sources: Reuters reporting
Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.
Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.
© 2026 Border Cyber Group. All rights reserved.
Member discussion: