Cybersecurity Radar — 2026-09-07
CISA has added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a critical Chrome zero-day (CVE-2026-85046) with a mandatory patch deadline of September 18. Simultaneously, the "Panzer" ransomware-as-a-service operation is aggressively targeting global infrastructure, while threat actors are exploiting authentication bypass flaws in PaperCut servers to compromise educational institutions.
Cybersecurity Radar — 2026-09-07
🔴 Critical Alerts
Chrome V8 Zero-Day (CVE-2026-85046) Under Active Attack Google has released an emergency update for Chrome to patch CVE-2026-85046, a high-severity zero-day vulnerability in the V8 JavaScript engine. The flaw allows attackers to execute arbitrary code inside the sandbox via crafted HTML pages. This is the sixth actively exploited Chrome zero-day of 2026. CISA has added this flaw to the KEV catalog with a strict federal patch deadline of September 18, 2026. Users and organizations must update Chrome immediately to version 152 or later.

CISA Adds Seven Exploited Flaws to KEV Catalog In addition to the Chrome flaw, CISA has added six other vulnerabilities to its KEV catalog affecting SonicWall, Artifactory, Switchvox, Starlette, Kestra, and LiteLLM. Threat actors are actively deploying reverse shells and cryptocurrency miners using these exploits. Federal agencies are required to remediate these vulnerabilities by September 18, 2026, while private sector entities are strongly urged to do the same to prevent supply chain compromises.
Threat Landscape
Panzer Ransomware Targets Global Infrastructure The "Panzer" ransomware-as-a-service (RaaS) operation is currently slashing through global defenses, having already hit 16 organizations across 11 countries. The campaign employs a double-extortion strategy involving data theft and file encryption. Primary targets include the technology, manufacturing, and government sectors. Security teams should monitor for unusual file access patterns and ensure offline backups are intact, as Panzer operators are known to exfiltrate sensitive data prior to encryption.

PaperCut Servers Exploited in Education Sector Threat actors are exploiting a chain of vulnerabilities in PaperCut servers, specifically targeting the education sector. The attacks utilize CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution) to conduct command execution and reconnaissance. Post-exploitation activities include delivering Windows registry hive collection tools and Metasploit/Meterpreter-related Java payloads. Arctic Wolf researchers observed these attacks impacting organizations ranging from K-12 schools to major universities in the U.S.
Vulnerabilities & Patches
VMware Workstation and Fusion Host Code Execution Flaws Broadcom has patched two critical vulnerabilities in VMware Workstation and Fusion that allow local virtual machine administrators to execute code on the host system. While no active exploitation is known at this time, the severity of these flaws poses a significant risk to environments relying on virtualization for isolation. Administrators should apply the latest updates immediately to prevent potential sandbox escapes.

Citrix NetScaler Authentication Bypass (CVE-2026-19490) Attackers have begun targeting a critical-severity authentication bypass flaw in Citrix NetScaler, tracked as CVE-2026-19490. Vulnerability intelligence company Previdian reports that exploitation is occurring in the wild. Organizations using Citrix NetScaler ADC and NetScaler Gateway must verify their current patch status and apply vendor mitigations immediately to prevent unauthorized access.
Breaches & Incidents
No recent confirmed data breaches or organizational compromises were reported in the last 24 hours from verified sources.
Industry & Policy
No significant regulatory changes or major industry policy announcements were identified in the last 24 hours.
What to Watch
- September 18 Federal Deadline: Monitor compliance efforts for the CISA-mandated remediation of the seven newly added KEV vulnerabilities, including the Chrome V8 zero-day.
- Panzer Ransomware Expansion: Track the geographic spread of Panzer RaaS, particularly as it moves beyond initial targets in technology and manufacturing into critical infrastructure sectors.
- Post-Patch Exploitation Attempts: Watch for increased scanning and exploitation attempts against unpatched VMware Workstation/Fusion installations following the disclosure of host code execution flaws.
Reader Action Items
- Patch Chrome Immediately: Ensure all endpoints are running Chrome version 152 or later to mitigate the actively exploited V8 zero-day (CVE-2026-85046).
- Review PaperCut Security: Educational institutions and organizations using PaperCut should verify they have patched CVE-2026-81578 and CVE-2026-82078 and audit logs for signs of unauthorized access or payload delivery.
- Update Virtualization Infrastructure: Apply Broadcom’s latest patches for VMware Workstation and Fusion to close the local-to-host code execution gaps, even if no active exploitation is currently observed.
This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.