An actively exploited Chrome zero-day is the most immediate threat in the cybersecurity bulletin published on 7 September 2026. The update also covers an exploited Magento and Adobe Commerce flaw, plus an unverified privilege escalation claim involving CrowdStrike Falcon Sensor.
Each issue is at a different stage. Google has released patched Chrome versions, Magento and Adobe Commerce users are awaiting a vendor fix, and CrowdStrike is investigating the FalconFlank research while providing interim configuration guidance.
Chrome zero-day CVE-2026-85046 is under attack
Google has issued an emergency desktop update for CVE-2026-85046, a high-severity vulnerability in Chrome’s V8 JavaScript engine. The Chrome zero-day is being actively exploited in the wild, making browser updates the clearest immediate priority from this week’s bulletin.
The vulnerability was reported by security researcher Salvatore Gulizia. It is classified as a type confusion flaw, a memory safety problem that arises when software allocates memory for one object type but later accesses that memory as though it contains a different type of object.
That mismatch can cause memory corruption and may create a route to arbitrary code execution within the browser process. An attacker could attempt to trigger the flaw through JavaScript placed on a specially crafted web page.
Chrome versions containing the fix
The Chrome zero-day has been addressed in the following Stable channel desktop releases:
- Chrome 152.0.7977.82 or 152.0.7977.83 for Windows.
- Chrome 152.0.7977.82 or 152.0.7977.83 for macOS.
- Chrome 152.0.7977.82 for Linux.
Organisations should verify the installed version rather than assume that automatic updating has completed. Browsers that remain open for long periods may have downloaded an update but still require a restart before the corrected version is active.
How attackers can reach potential victims
Exploitation generally requires a target to visit maliciously prepared web content. Delivery could involve a phishing message, malicious advertising, or a legitimate website that has been compromised and altered to serve exploit code.
Because the Chrome zero-day is already being used in real attacks, organisations should treat exposure as current rather than theoretical. The available information does not identify the attackers, their targets, or the scale of exploitation, but Google’s active exploitation status is sufficient reason to accelerate deployment.
StyleSmuggler targets Magento and Adobe Commerce
The second urgent development concerns an unauthenticated remote code execution vulnerability affecting Magento Open Source and Adobe Commerce. E-commerce security company Sansec named the flaw StyleSmuggler and reported that it is being actively exploited against merchant storefronts.
According to the bulletin, the vulnerability affects all supported builds, including version 2.4.9. Fully patched storefronts have reportedly been compromised, which means applying previously available security updates does not address this particular zero-day.
GraphQL queries smuggle PHP into internal files
The attack begins with unauthenticated GraphQL queries. Attackers manipulate style properties within those queries to smuggle PHP code into log and report files written internally by the commerce platform.
The malicious code is then executed when Magento internally renders its standard payment failure notification email. No recipient needs to open the email or click a link, so the execution stage does not depend on further user interaction.
After obtaining code execution, the reported dropper tries multiple PHP execution functions. Its objective is to install a persistent binary written in Rust and disguised as a legitimate kernel thread, helping the malicious process blend into activity on the affected host.
No official vendor patch is available
The bulletin states that an official vendor patch has not yet been released. This places Magento and Adobe Commerce operators in a mitigation phase, rather than the more straightforward patching position available for the Chrome zero-day.
Suggested temporary measures include disabling GraphQL where operationally feasible and restricting process execution permissions. Any GraphQL change should be tested against storefront, checkout and integration requirements, while process restrictions should be designed to prevent the web application from launching unnecessary executables.
Operators should also investigate unexpected PHP content in log or report files and unfamiliar persistent binaries. These checks are specifically connected to the reported StyleSmuggler chain and may help identify systems that were attacked before mitigations were introduced.
CrowdStrike FalconFlank claim remains unverified
A researcher using the alias Nightmare-Eclipse has published a proof-of-concept project called FalconFlank. The project alleges a local privilege escalation vulnerability in CrowdStrike Falcon Sensor, but the claim remained unverified in the information published on 7 September 2026.
The claimed issue affects Windows 11 and Windows Server 2025 systems operating with Phase 3 Optimal Protection. It allegedly abuses the sensor’s remediation workflow when Falcon removes malicious Microsoft Office macros.
Why the remediation workflow matters
Endpoint security agents require elevated permissions so they can quarantine threats, alter files and perform remediation actions across a system. FalconFlank claims that a local user with limited privileges can manipulate this trusted workflow and obtain SYSTEM privileges.
This is not described as a remote initial access vulnerability. The proof of concept assumes a local low-privileged position, which an attacker might seek to elevate. However, organisations should avoid treating the claimed exploitation path as confirmed while CrowdStrike’s investigation is continuing.
CrowdStrike advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting temporarily, while keeping Cloud Anti-malware protection enabled. Customers have also been directed to the FalconFlank Tech Alert in the CrowdStrike customer portal for continuing updates.
What organisations should prioritise
The three developments require distinct responses based on their current status. The Chrome zero-day has a vendor patch and confirmed active exploitation, StyleSmuggler has reported exploitation but no official patch, and FalconFlank remains an allegation under investigation.
- Deploy the corrected Chrome Stable versions across Windows, macOS and Linux endpoints, then confirm browsers have restarted.
- Identify Magento Open Source and Adobe Commerce systems, assess temporary GraphQL restrictions, and limit unnecessary process execution.
- Review commerce servers for the reported PHP file manipulation and persistent Rust binary behaviour.
- Follow CrowdStrike’s interim policy advice and monitor the customer portal alert rather than relying solely on the public proof of concept.
Prioritisation should follow evidence and available remedies. That puts the Chrome zero-day first for broad endpoint fleets, while internet-facing commerce platforms require focused mitigation and investigation because StyleSmuggler is reportedly active without a vendor patch.
Originally reported by cybersecuritynews.com.







