Two Chrome Zero-Days in a Week, Plus a Firewall Alert: What to Check Now

Google patched two actively exploited Chrome zero-days within a week, while CISA flagged actively exploited flaws in Cisco, Citrix and Fortinet security gear. Here's what Perth businesses should check this week. From Computer Mechanics, Perth IT specialists since 1997.

XanderXander · Web Developer & IT Technician
14 September 2026
5 min read
Cybersecurity
Browser Security
Patch Management
Perth Business
A padlock over a laptop and network device representing browser and firewall vulnerabilities under active attack

Google patched two actively exploited Chrome zero-days within a single week this month, and in the same week CISA flagged actively exploited flaws in Cisco, Citrix and Fortinet security appliances that sit at the edge of business networks. If your business runs Windows, Mac or Chromebooks, the fix for the browser issue is simple: restart every browser this week. If you also have a Fortinet, Citrix or Cisco firewall or VPN gateway, that needs checking too — those are the boxes an attacker would love to bypass without needing a password at all.

Two Chrome zero-days, back to back

On 4 September, Google shipped an emergency Chrome update for CVE-2026-85046, a type confusion bug in Chrome's V8 JavaScript engine that a researcher found being exploited in the wild. Google confirmed an exploit existed before most users had even received the patch. Days later, on 9-10 September, CISA added a second actively exploited Chromium V8 flaw, CVE-2026-87491, to its Known Exploited Vulnerabilities catalogue in the same batch as the Cisco, Citrix and Fortinet flaws below. That makes it the sixth and seventh Chrome zero-day Google has had to patch this year.

Both bugs live in the part of Chrome that runs the JavaScript on every webpage you visit. In practice, that means simply opening a booby-trapped page — no download, no click on a fake button — can be enough for an attacker to run code on the machine. It's the same engine that powers Microsoft Edge and most other Chromium-based browsers, so this isn't just a "Chrome problem."

Why a security update doesn't help until you restart

Chrome and Edge quietly download security updates in the background, but the new code only takes effect once the browser fully restarts — not just when you close and reopen a tab, and not always overnight if staff put laptops to sleep rather than shutting down. A browser that's been open for days can still be running the vulnerable version even though an update has technically "installed."

The fix takes thirty seconds: open Chrome's menu and look for an "Update" button, or go to chrome://settings/help (Edge: edge://settings/help) to force a check and see the version number. If it prompts to relaunch, do it. For a whole office, it's worth sending staff a one-line reminder this week rather than assuming it happens on its own.

Firewalls and VPN gateways under attack too

The bigger worry from the same fortnight sits at the edge of the network, not inside a browser tab. CISA's 9 September update to its Known Exploited Vulnerabilities catalogue included:

  • CVE-2026-20079 — an authentication bypass in Cisco's Secure Firewall Management Center, rated a maximum CVSS of 10.0. Cisco has already observed attackers using it to plant web shells and malware after skipping the login screen entirely.
  • CVE-2026-19490 — an authentication bypass affecting Citrix NetScaler ADC and Gateway, the kind of appliance many businesses use for secure remote access.
  • CVE-2025-25249 — a buffer overflow in Fortinet FortiOS, FortiSwitchManager and FortiSASE that lets an unauthenticated attacker run their own code.

CISA gave US federal agencies until 12 September to patch all three. That deadline doesn't apply to an Australian small business, but the underlying fact does: these are authentication bypasses, meaning the flaw isn't "an attacker needs your password" — it's "an attacker doesn't need a password at all." A firewall or VPN gateway is meant to be the locked front door to your network; a bypass in the door itself is about as bad as this gets.

Why this keeps happening to edge devices

We wrote in August about a Windows VPN flaw (CVE-2026-33824) being used the same way, and before that about attackers breaking into a remote-management platform through its own login screen. The pattern across all three is the same: internet-facing security and access devices — VPNs, firewalls, remote management consoles — are now a favourite target precisely because they're designed to be reachable from anywhere and trusted once you're through. Attackers only need to find the one appliance that's a version or two behind.

What to check this week

You don't need to know whether you personally run Cisco, Citrix or Fortinet gear to act on this — most businesses don't manage their own firewall and rely on whoever supports their network to know. What's worth doing regardless:

  • Restart browsers fleet-wide. Chrome and Edge update automatically, but only after a relaunch — make it happen this week rather than waiting for the next reboot.
  • Ask your IT provider directly whether any Cisco, Citrix or Fortinet device on your network is affected by the three CVEs above, and when it was last patched.
  • Check that automatic updates are actually enabled on browsers and on any security appliance's firmware — a surprising number get left on manual update and quietly fall behind.
  • Turn on multi-factor authentication on any remote-access gateway where it's available, so an authentication bypass in the software isn't the only thing standing between an attacker and your network.

None of this requires new hardware or a big project — it's a browser restart and a five-minute question to whoever manages your network security. The businesses that get caught out by weeks like this one are almost always the ones nobody asked.

If you're not sure what's sitting at the edge of your network or when it was last patched, our IT security solutions and firewall service cover exactly this kind of check, and it's worth reading how the Windows VPN flaw from last month played out for context. For an ongoing patching routine rather than a once-off scramble, that's what managed IT support is for. We're a Perth IT provider that's been keeping local businesses patched and online since 1997.

Xander
Written by
Xander
Web Developer & IT Technician · 2+ years in IT

Xander builds fast, SEO-friendly websites and handles hands-on IT and computer-repair work — from Next.js builds and local search optimisation through to hardware fixes, OS reinstalls and helpdesk support. He covers the full stack, from the rack to the browser.

Meet the IT Support Perth team →
Xander
14 September 2026
5 min read
Cybersecurity
Browser Security
Patch Management
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Passkeys Are Now Default in Microsoft 365: What Perth Businesses Must Check

Microsoft has switched Entra ID to passkeys by default and is retiring SMS and voice sign-in codes by February 2027. Here's what Perth businesses need to check now. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Copilot Is Now Built Into Microsoft 365 Business: Decide Before 30 September

Microsoft has made Copilot a permanent part of its small business plans, with a discounted add-on price ending 30 September 2026. Here's what Perth businesses should check first. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

September 2026 Patch Tuesday Was Microsoft's Biggest Ever: What Perth Businesses Should Check

Microsoft's September 2026 Patch Tuesday fixed a record 966 flaws, including two zero-days already under attack — one inside Windows Update itself. Here's what Perth businesses need to check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

September 2026 Patch Tuesday Was Microsoft's Biggest Ever: What Perth Businesses Should Check
Cybersecurity
Patch Management

September 2026 Patch Tuesday Was Microsoft's Biggest Ever: What Perth Businesses Should Check

Microsoft's September 2026 Patch Tuesday fixed a record 966 flaws, including two zero-days already under attack — one inside Windows Update itself. Here's what Perth businesses need to check. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/9/2026
Microsoft's August 2026 Patch Tuesday Fixed a Flaw Already Under Attack: What to Do
Cybersecurity
Patch Management

Microsoft's August 2026 Patch Tuesday Fixed a Flaw Already Under Attack: What to Do

Microsoft's August 2026 security update patched a Windows flaw that was already being exploited to seize full control of machines, plus a critical SharePoint hole. Here's what Perth businesses need to check this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/12/2026
SIM-Swap Fraud Is Rising Again: What It Means for Your Perth Business Accounts
Cybersecurity
Scams

SIM-Swap Fraud Is Rising Again: What It Means for Your Perth Business Accounts

Reports of SIM-swap and phone port-out fraud are climbing in Australia, and the target is usually the SMS codes protecting your business banking and email. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
9/9/2026
Call us