Google patched two actively exploited Chrome zero-days within a single week this month, and in the same week CISA flagged actively exploited flaws in Cisco, Citrix and Fortinet security appliances that sit at the edge of business networks. If your business runs Windows, Mac or Chromebooks, the fix for the browser issue is simple: restart every browser this week. If you also have a Fortinet, Citrix or Cisco firewall or VPN gateway, that needs checking too — those are the boxes an attacker would love to bypass without needing a password at all.
Two Chrome zero-days, back to back
On 4 September, Google shipped an emergency Chrome update for CVE-2026-85046, a type confusion bug in Chrome's V8 JavaScript engine that a researcher found being exploited in the wild. Google confirmed an exploit existed before most users had even received the patch. Days later, on 9-10 September, CISA added a second actively exploited Chromium V8 flaw, CVE-2026-87491, to its Known Exploited Vulnerabilities catalogue in the same batch as the Cisco, Citrix and Fortinet flaws below. That makes it the sixth and seventh Chrome zero-day Google has had to patch this year.
Both bugs live in the part of Chrome that runs the JavaScript on every webpage you visit. In practice, that means simply opening a booby-trapped page — no download, no click on a fake button — can be enough for an attacker to run code on the machine. It's the same engine that powers Microsoft Edge and most other Chromium-based browsers, so this isn't just a "Chrome problem."
Why a security update doesn't help until you restart
Chrome and Edge quietly download security updates in the background, but the new code only takes effect once the browser fully restarts — not just when you close and reopen a tab, and not always overnight if staff put laptops to sleep rather than shutting down. A browser that's been open for days can still be running the vulnerable version even though an update has technically "installed."
The fix takes thirty seconds: open Chrome's menu and look for an "Update" button, or go to chrome://settings/help (Edge: edge://settings/help) to force a check and see the version number. If it prompts to relaunch, do it. For a whole office, it's worth sending staff a one-line reminder this week rather than assuming it happens on its own.
Firewalls and VPN gateways under attack too
The bigger worry from the same fortnight sits at the edge of the network, not inside a browser tab. CISA's 9 September update to its Known Exploited Vulnerabilities catalogue included:
- CVE-2026-20079 — an authentication bypass in Cisco's Secure Firewall Management Center, rated a maximum CVSS of 10.0. Cisco has already observed attackers using it to plant web shells and malware after skipping the login screen entirely.
- CVE-2026-19490 — an authentication bypass affecting Citrix NetScaler ADC and Gateway, the kind of appliance many businesses use for secure remote access.
- CVE-2025-25249 — a buffer overflow in Fortinet FortiOS, FortiSwitchManager and FortiSASE that lets an unauthenticated attacker run their own code.
CISA gave US federal agencies until 12 September to patch all three. That deadline doesn't apply to an Australian small business, but the underlying fact does: these are authentication bypasses, meaning the flaw isn't "an attacker needs your password" — it's "an attacker doesn't need a password at all." A firewall or VPN gateway is meant to be the locked front door to your network; a bypass in the door itself is about as bad as this gets.
Why this keeps happening to edge devices
We wrote in August about a Windows VPN flaw (CVE-2026-33824) being used the same way, and before that about attackers breaking into a remote-management platform through its own login screen. The pattern across all three is the same: internet-facing security and access devices — VPNs, firewalls, remote management consoles — are now a favourite target precisely because they're designed to be reachable from anywhere and trusted once you're through. Attackers only need to find the one appliance that's a version or two behind.
What to check this week
You don't need to know whether you personally run Cisco, Citrix or Fortinet gear to act on this — most businesses don't manage their own firewall and rely on whoever supports their network to know. What's worth doing regardless:
- Restart browsers fleet-wide. Chrome and Edge update automatically, but only after a relaunch — make it happen this week rather than waiting for the next reboot.
- Ask your IT provider directly whether any Cisco, Citrix or Fortinet device on your network is affected by the three CVEs above, and when it was last patched.
- Check that automatic updates are actually enabled on browsers and on any security appliance's firmware — a surprising number get left on manual update and quietly fall behind.
- Turn on multi-factor authentication on any remote-access gateway where it's available, so an authentication bypass in the software isn't the only thing standing between an attacker and your network.
None of this requires new hardware or a big project — it's a browser restart and a five-minute question to whoever manages your network security. The businesses that get caught out by weeks like this one are almost always the ones nobody asked.
If you're not sure what's sitting at the edge of your network or when it was last patched, our IT security solutions and firewall service cover exactly this kind of check, and it's worth reading how the Windows VPN flaw from last month played out for context. For an ongoing patching routine rather than a once-off scramble, that's what managed IT support is for. We're a Perth IT provider that's been keeping local businesses patched and online since 1997.



