Summary: Google released Chrome 152.0.7977.82/.83 (Windows/macOS) and 152.0.7977.82 (Linux) to address 12 vulnerabilities, including the high-severity type-confusion flaw CVE-2026-85046 in the V8 JavaScript engine. Google stated an exploit for CVE-2026-85046 exists in the wild. The bug, reported by researcher Salvatore Gulizia, can allow remote code execution inside the sandbox via a crafted HTML page. This is Google’s sixth actively exploited Chrome zero-day of 2026.
Key takeaway / Actionable note: Update Chrome immediately via Settings > About Chrome and restart; Chromium-based browsers (Edge, Brave, etc.) should follow as soon as their updates land.
Summary: The FulcrumSec extortion group published roughly 550 GB of data stolen from Manchester Airports Group after the operator reportedly refused a ransom demand. The dump includes personal information of approximately 8.8 million people (email addresses, phone numbers, vehicle registrations, postcodes, and booking data) from Manchester, London Stansted, and East Midlands airports. Attackers claimed access via exposed admin keys left in frontend JavaScript on the airports’ websites. MAG confirmed operations were unaffected.
Key takeaway / Actionable note: Organizations should audit public-facing JavaScript for hardcoded credentials or keys and rotate any exposed secrets immediately.
Summary: Thomson Reuters disclosed that an unauthorized party obtained files from its C-Track court case management platform in March 2026. The incident, discovered June 30, affected courts in at least 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. Some records may contain names, Social Security numbers, driver’s license numbers, medical information, dates of birth, health insurance details, and confidential, redacted, or sealed information. The company said there is no evidence of operational disruption or confirmed misuse to date and is offering credit monitoring.
Key takeaway / Actionable note: Courts and legal teams relying on third-party case-management platforms should verify vendor incident notifications and monitor for identity-theft activity involving litigants and court personnel.
Summary: Wordfence reported more than 440,000 blocked exploitation attempts against two critical WordPress plugin flaws: CVE-2026-14894 in Super Forms (arbitrary file upload leading to RCE, fixed in 6.3.314) and CVE-2026-32475 in Elementor Pro (file-upload validation bypass leading to RCE, fixed in 4.2.2). Attackers are uploading PHP webshells; exploitation of the Elementor issue requires a published form with a File Upload field. Activity against Elementor Pro began the same day the patch was released.
Key takeaway / Actionable note: Immediately update Elementor Pro to 4.2.2+ and Super Forms to 6.3.314+; inspect /wp-content/uploads/elementor/forms/ and similar directories for unexpected PHP files.
Summary: Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that served malicious Terraform modules containing credential-stealing code between 07:35 and 21:45 UTC on August 31. The modules targeted provisioner environment variables, cloud and AI API keys, CI/CD credentials, SSH keys, OIDC tokens, and other secrets, exfiltrating them to a lookalike domain. Coder released patched versions and provided detection queries; no evidence of impact to customer data maintained by Coder was reported.
Key takeaway / Actionable note: Rotate any secrets potentially exposed during the window, check logs for connections to the attacker domain, and purge cached modules downloaded in that timeframe.
Summary: Cyera disclosed CVE-2026-6471 (PostGREShell), a missing-authorization issue in PostgreSQL logical decoding present since version 9.4. An attacker with Replication privileges can load arbitrary shared libraries via a crafted plugin path, achieve code execution as the postgres user, escalate to permanent superuser, and install a persistent backdoor. The flaw is fixed in PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24.
Key takeaway / Actionable note: Patch affected PostgreSQL instances promptly and remove the Replication attribute from any accounts that do not require it.
Summary: HPE released patches for CVE-2026-73749, a critical buffer-overflow vulnerability in an ArubaOS-CX daemon that allows unauthenticated remote attackers to achieve elevated code execution by sending crafted packets. Multiple additional high-severity issues (including authenticated RCE, file-write, and authentication-bypass flaws) were also addressed across AOS-CX branches 10.10 through 10.18. HPE stated it was not aware of active exploitation at the time of the advisory.
Key takeaway / Actionable note: Upgrade ArubaOS-CX switches to the fixed releases listed in HPE’s bulletin as soon as possible.
Summary: Plex released Media Server 1.43.3 and Desktop 1.115.0 to address multiple undisclosed security vulnerabilities affecting versions 1.43.2 and earlier. The company emailed affected users and requested CVE assignments. Details have not yet been published.
Key takeaway / Actionable note: Update Plex Media Server and Desktop clients immediately; NAS users may need to install the package manually if the vendor package manager has not yet updated.
Summary: VMware released updates for Workstation and Fusion that address a critical vulnerability allowing an attacker with administrative access to a virtual machine to execute code on the host system.
Key takeaway / Actionable note: Apply the latest Workstation and Fusion patches without delay, especially on systems where guest VMs are not fully trusted.
Also Noted:
Bottom line: The last 24 hours were dominated by actively exploited browser and CMS flaws, a large-scale airport data dump, a significant court-records platform breach, and a supply-chain hit on a developer platform. Prioritize browser and WordPress plugin updates today, verify third-party vendor exposure notifications, and treat any publicly exposed credentials or keys as already compromised.

