A Chrome Zero-Day and 440,000 Exploit Attempts (09/04/2026)

September 4, 2026
A Chrome Zero-Day and 440,000 Exploit Attempts (09/04/2026)
Key Intel / TL;DR
  • Google patched CVE-2026-85046, a type confusion flaw in Chrome's V8 engine already under active exploitation, alongside 11 other bugs.
  • Wordfence counted more than 440,000 exploit attempts against critical flaws in the Super Forms and Elementor Pro WordPress plugins.
  • Cisco found enough IOS XR bugs to bundle them into a release, including a root-level Nexus 9000 flaw you can mitigate but not fix.
  • Plex is urging immediate updates for undisclosed flaws fixed in Media Server 1.43.3 and Desktop 1.115.0.
  • The Phantom Deal campaign studies target companies in detail, then convinces midlevel employees to initiate large transfers.

The gap that matters today is between how fast a flaw gets weaponized and how fast an organization can act on it. Google shipped a fix for a browser bug that was already being used against people, Wordfence counted 440,000 attempts against two plugins, and a model crossed the critical threshold on an exploit-writing benchmark. Only one of those three clocks runs at the speed of your change window.

Top 5 Critical Security Alerts

1. Chrome V8 Zero-Day Is Already Being Exploited

Google released updates patching 12 vulnerabilities in Chrome, including CVE-2026-85046, a high-severity type confusion bug in the V8 JavaScript and WebAssembly engine that has come under active exploitation in the wild. A browser flaw under exploitation deserves different handling from a browser flaw in a bulletin, because the browser is the one piece of software on every endpoint that renders untrusted code from strangers all day. Force the restart rather than waiting for users to close their tabs. The Hacker News has the CVE detail and BleepingComputer covers the update.

Operator Note: Chrome patches on relaunch, so a fleet with 40-day uptime is a fleet that is still vulnerable next week no matter what your patch dashboard reports.

2. Wordfence Counts 440,000 Attempts Against Two WordPress Plugins

Threat actors are exploiting two critical flaws in the Super Forms and Elementor Pro plugins, including CVE-2026-14894, a missing file type validation vulnerability in Super Forms carrying a CVSS score of 9.8. The attempt count is the useful number here, because 440,000 tells you this is automated scanning of the entire internet rather than anybody choosing you. Missing file type validation means an attacker uploads what they like and asks the server to run it. The Hacker News has the Wordfence findings.

Operator Note: Your marketing site runs plugins nobody in security has inventoried, and it usually shares a network or a credential with something that matters.

3. Cisco Bundles a Release Worth of IOS XR Bugs

Cisco went looking for bugs in IOS XR and found enough of them to roll the fixes into an update release, with three critical issues demanding attention. One is a root-level flaw in Nexus 9000 Series switches that can be mitigated but not actually fixed, which is a materially different instruction from the patch guidance issued earlier this week. A mitigation is a configuration change somebody has to make and keep, and it does not survive a device being rebuilt from a template. The Register has the breakdown.

4. Plex Urges Immediate Updates Without Saying Why

Plex is telling users to update to Plex Media Server 1.43.3 and Plex Desktop 1.115.0, which fix multiple security flaws the company has declined to describe. Withholding detail buys defenders a little time and buys attackers a diff of the two releases, and the second group is better resourced for that work. Undisclosed usually means serious enough that the vendor would rather you patched before you understood. The Hacker News has the version numbers.

5. Phantom Deal Fakes an Acquisition to Move Real Money

The threat actors behind the Phantom Deal campaign research target companies in extreme detail, then approach midlevel employees with a fabricated merger or acquisition to get large financial transfers initiated. Targeting the middle of the organization is the clever part, because a director has enough authority to start a payment and rarely enough standing to question a deal the executive team is supposedly running. Secrecy is built into a real acquisition, which removes the one control that would otherwise catch this. Dark Reading has the campaign detail.

Operator Note: The control is a payment verification path that does not route through the person requesting the payment, and it has to be usable by somebody who has been told the deal is confidential.

Additional Security Alerts

Emerging Security Technologies

  • GPT-6 Astra scores 100% on ExploitBench: OpenAI unveiled the model days after saying it had reached the Critical cybersecurity capability threshold under its Preparedness Framework, and the company is blocking proof of concept exploit requests. The Hacker News
  • OpenAI pledges $1bn to put AI security tooling in essential services: The company is subsidizing access to Daybreak so defenders at critical service providers can deploy its models inside existing security infrastructure. Infosecurity Magazine
  • AI coding agents are installing untrusted code on corporate networks: Researchers scanned 6,214 live domains belonging to defense contractors, Fortune 500, and large technology companies, and found 8,265 llms.txt and llms-full.txt files shaping what agents fetch and run. Schneier on Security

Threat Intelligence

  • Drone wreckage in Ukraine is feeding a data marketplace: The data generated by drones will outlast the conflicts they were flown in, and a defense-sector market has formed around collecting and reselling it. MIT Technology Review

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)