Eight More Chromium Bugs Confirmed Exploited, Beyond V8
V8, Dawn, Skia, ANGLE, and Chromium's CSS engine each produced confirmed-exploited vulnerabilities — ten total this year across five distinct browser subsystems.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
V8, Dawn, Skia, ANGLE, and Chromium's CSS engine each produced confirmed-exploited vulnerabilities — ten total this year across five distinct browser subsystems.
Use-after-free, memory corruption, integer overflow — nine Apple vulnerabilities spanning nearly a decade of disclosure dates were confirmed exploited across the company's full platform range.
CVE-2026-20131 in Cisco FMC carries CISA's confirmed ransomware flag — the second FMC vulnerability covered in this series, alongside new findings in Email Gateway, ASA/FTD, and Unified CM.
From a perfect-10 peering authentication bypass to CLI privilege escalation, seven distinct vulnerabilities across Cisco's SD-WAN Controller, Manager, and underlying software were confirmed exploited.
Nine local privilege-escalation and access-control vulnerabilities in Windows were confirmed exploited over the past year. None individually dramatic, together they define how far an intrusion spreads.
Security software is software first: two local privilege-escalation bugs and a denial-of-service flaw in Microsoft Defender itself were confirmed exploited in the wild.
Beyond the five-CVE cluster covered earlier, four more SharePoint and Exchange vulnerabilities were confirmed exploited across the year — including a 2023 Exchange bug confirmed nearly three years later.
CVE-2025-59287 in WSUS and CVE-2024-43468 in Configuration Manager both scored CVSS 9.8 — critical bugs in the very tools organizations use to distribute trust across their fleet.
A Windows buffer overflow from 2008, IE bugs from 2010, an Office flaw from 2009 — eleven old Microsoft vulnerabilities entered CISA's KEV catalogue, several on the exact same day.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.