⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
This week's security landscape is dominated by active exploitation campaigns targeting Google Chrome, MikroTik RouterOS, and N-able N-central. Google addressed a high-severity type confusion bug in the V8 engine (CVE-2026-85046) that is currently under attack, while CERT Polska warned of a critical zero-day chain dubbed MikroTrick being used to hijack routers via SSH.
N-able released urgent hotfixes for two severe authentication bypass flaws (CVE-2026-86206 and CVE-2026-86207) and a CVSS 10.0 remote code execution vulnerability (CVE-2026-86218), with evidence suggesting attackers are already leveraging these weaknesses. Additionally, e-commerce platforms are suffering from an unpatched Magento and Adobe Commerce zero-day known as StyleSmuggler, which allows unauthenticated attackers to inject backdoors into online stores.