CVE Tools

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

The Hacker NewsBy The Hacker News

Reported exploitedN-centralGoogle Chrome

Our summary

This week's security landscape is dominated by active exploitation campaigns targeting Google Chrome, MikroTik RouterOS, and N-able N-central. Google addressed a high-severity type confusion bug in the V8 engine (CVE-2026-85046) that is currently under attack, while CERT Polska warned of a critical zero-day chain dubbed MikroTrick being used to hijack routers via SSH.

N-able released urgent hotfixes for two severe authentication bypass flaws (CVE-2026-86206 and CVE-2026-86207) and a CVSS 10.0 remote code execution vulnerability (CVE-2026-86218), with evidence suggesting attackers are already leveraging these weaknesses. Additionally, e-commerce platforms are suffering from an unpatched Magento and Adobe Commerce zero-day known as StyleSmuggler, which allows unauthenticated attackers to inject backdoors into online stores.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store