⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Reported exploitedN-centralGoogle ChromeOur summary
This week's security landscape is dominated by active exploitation campaigns targeting Google Chrome, MikroTik RouterOS, and N-able N-central. Google addressed a high-severity type confusion bug in the V8 engine (CVE-2026-85046) that is currently under attack, while CERT Polska warned of a critical zero-day chain dubbed MikroTrick being used to hijack routers via SSH.
N-able released urgent hotfixes for two severe authentication bypass flaws (CVE-2026-86206 and CVE-2026-86207) and a CVSS 10.0 remote code execution vulnerability (CVE-2026-86218), with evidence suggesting attackers are already leveraging these weaknesses. Additionally, e-commerce platforms are suffering from an unpatched Magento and Adobe Commerce zero-day known as StyleSmuggler, which allows unauthenticated attackers to inject backdoors into online stores.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.