Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subseque...
Google has released an emergency update for Chrome to address CVE-2026-85046, a high-severity zero-day vulnerability in the V8 JavaScript and WebAssembly engine, rated 8.8 on the CVSS scale. The flaw, identified as a type confusion issue, allows remote attackers to execute arbitrary code within Chro...
Multiple vulnerabilities have been identified in Microsoft Edge, with CVE-2026-3910 and CVE-2026-3909 both being exploited in the wild. These vulnerabilities allow remote attackers to execute arbitrary code, bypass security restrictions, and manipulate data via crafted HTML pages. The risk level for...
On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing sig...