Article

    Cyber News / Article / ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

    ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
    in
    [email protected] (The Hacker News)-4 days ago

    ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

    Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.

    Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches.

    Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week.

    N-able Patches Critical N-central Flaws— N-able has released hotfixes to address two severe N-central flaws (CVE-2026-86206 and CVE-2026-86207) that could allow an unauthorized party to bypass authentication controls and gain full access to the platform. Also patched is a maximum-severity security flaw (CVE-2026-86218, CVSS score: 10.0) that could allow for pre-authenticated remote code execution on the N-central server. "At this time, we have no confirmation that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk," N-able said. However, Huntress said it observed signs that attackers are likely leveraging CVE-2026-86206 or/and CVE-2026-86207, after it launched an investigation on September 4 following the compromise of a customer's fully patched N-central production environment. "However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities," it said.

    Imagine you’ve received a water bill for 500,000,000 gallons. Now, you have to account for every teaspoon of that water. IT leaders face a similar task when managing AI budgets, and it’s not as simple as token caps or model limits. Learn how your team can optimize your company's AI spend.

    Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.

    Check the list, patch what you have, and hit the ones marked urgent first —CVE-2026-78174, CVE-2026-19313, CVE-2026-19318, CVE-2026-19315, CVE-2026-57910, CVE-2026-57909, CVE-2026-13086(WatchGuard),CVE-2026-80047(Hugging Face Transformers),CVE-2026-9585, CVE-2026-9586, CVE-2026-9587, CVE-2026-9588(Sangoma Switchvox SMB),CVE-2026-6881(Ellucian Advance Web and Legacy Advance),CVE-2026-13381, CVE-2026-13380(VSee Clinic),CVE-2026-63219, CVE-2026-58400(GeoNetwork),CVE-2026-9637, CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-19471, CVE-2026-19472, CVE-2026-12663, CVE-2026-9633, CVE-2026-9634, CVE-2026-16675, CVE-2025-12768, CVE-2026-84235(Rockwell Automation),CVE-2026-84115(Cleo Harmony),CVE-2026-84117, CVE-2026-84118, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84122, CVE-2026-84123, CVE-2026-84124, CVE-2026-84125, CVE-2026-84126(Mozilla Firefox),CVE-2026-84353, CVE-2026-84352,CVE-2026-85046(Google Chrome),CVE-2026-19949(All-in-One WP Migration and Backup),CVE-2026-20277, CVE-2026-20278, CVE-2026-20280, CVE-2026-20279, CVE-2026-20276, CVE-2026-20275, CVE-2026-20274, CVE-2026-20212(Cisco),CVE-2026-15630(Casdoor),CVE-2026-73749(Hewlett Packard Enterprise ArubaOS-CX),CVE-2026-67394(Plesk),CVE-2026-38577(Tenda),CVE-2026-6471aka PostGREShell (PostgreSQL),CVE-2026-42038(Axios),CVE-2026-64532, CVE-2026-64533(Linux Kernel),CVE-2026-58048(cPanel and WHM),CVE-2026-14540(Google mcp-toolbox),CVE-2026-84645, CVE-2026-84647, CVE-2026-84648, CVE-2026-84649, CVE-2026-84650, CVE-2026-84652, CVE-2026-84665, CVE-2026-84667, CVE-2026-84668, CVE-2026-84669, CVE-2026-84670, CVE-2026-84671, CVE-2026-84672, CVE-2026-84673(Jenkins),GHSA-x7v6-xfx3-52j6,GHSA-r7jx-j9h7-j4xj,GHSA-9jcm-x588-gh26,GHSA-6mpx-c8rj-whj5,GHSA-q65v-4w7q-hx3r(FreeRDP),CVE-2026-59346, CVE-2026-59347(Broadcom VMware Workstation and Fusion),CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, CVE-2026-86060(MikroTik RouterOS),CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184, CVE-2026-13185, CVE-2026-13186, CVE-2026-13190(Telerik UI for ASP.NET AJAX),CVE-2026-86218,CVE-2026-86206, and CVE-2026-86207(N-able N-central).

    Trusted sources and safer settings still have limits. This week’s attacks show why it matters to know exactly what each protection covers—and what it leaves exposed.

    Keep patching, but keep the logs needed to investigate, too. “Fully patched” tells you which fixes are installed. It doesn’t prove nobody got in.

    Original source