Zero‑Day Vulnerabilities: Why This Wave Demands Immediate Action
Zero‑day vulnerabilities are previously unknown security flaws that attackers exploit before a fix is available, creating a window where systems are defenseless until vendors detect the issue, ship a patch, and users successfully apply that update across all affected devices. In the last few months, zero‑day vulnerabilities and other critical flaws have stacked up across browsers, operating systems, and enterprise tools, creating a dangerous backlog. Chrome alone has seen five exploited zero‑days, and a new Windows Defender local privilege escalation bug has been released with proof‑of‑concept code. At the same time, enterprise products from Fortinet, Ivanti, SAP, Cisco, and Arista are under active exploitation or carry critical CVSS 10.0 flaws. Security teams and individual users now face a clear priority: understand which zero‑day vulnerabilities matter to them and move from awareness to rapid patching.
Chrome’s Fifth Zero‑Day and the Growing Browser Patch Cycle
Google has shipped Chrome security patches for 74 vulnerabilities, including a high‑severity zero‑day, CVE‑2026‑11645, that is already exploited in the wild. This bug is an out‑of‑bounds read and write flaw in the V8 JavaScript engine that can allow remote code execution inside the browser sandbox via a crafted HTML page. It is fixed in Chrome 149.0.7827.102/.103 for Windows and macOS and 149.0.7827.102 for Linux, with updates rolling out now. According to Google’s advisory, “CVE‑2026‑11645 is the fifth Chrome zero‑day vulnerability Google has fixed in 2026,” following earlier bugs such as CVE‑2026‑2441 and CVE‑2026‑5281. The anonymous finder, using the handle "303f06e3," received a USD 55,000 (approx. RM253,000) bug bounty, showing how browser vendors incentivize fast reporting even as patch deployment remains a weak point for many users.

Enterprise Platforms: Fortinet, Ivanti, SAP and New CISA KEV Entries
Beyond browsers, enterprise platforms are facing critical CVSS 10.0 flaws and active exploitation threats. Fortinet fixed CVE‑2026‑25089, a command injection bug in FortiSandbox products (CVSS 9.1) that lets unauthenticated attackers execute OS commands via crafted HTTP requests. Ivanti patched two critical Ivanti Sentry issues: CVE‑2026‑10520, an unauthenticated command injection with CVSS 10.0 enabling root‑level remote code execution, and CVE‑2026‑10523 (CVSS 9.9), an authentication bypass that allows creation of arbitrary admin accounts. SAP has also released updates for multiple critical NetWeaver, Commerce Cloud, and Data Hub flaws. These moves align with new entries in the CISA KEV catalog: Cisco Catalyst SD‑WAN Manager (CVE‑2026‑20245), Chrome V8 (CVE‑2026‑11645), and Arista EOS (CVE‑2026‑7473), the last of which has no patch planned, despite reports it “has been reported as being exploited in the wild.”

Windows Defender RoguePlanet Zero‑Day and Escalation Risks
Independent researcher Nightmare Eclipse has disclosed a new Windows Defender zero‑day nicknamed RoguePlanet, complete with proof‑of‑concept exploit code. The flaw affects fully patched Windows 10 and Windows 11 systems and is a race‑condition‑based local privilege escalation issue that can grant SYSTEM‑level control if an attacker wins the race. RoguePlanet is the seventh Microsoft zero‑day they have released before an official fix, following earlier bugs such as RedSun, UnDefend, BlueHammer, YellowKey (CVE‑2026‑45585), GreenPlasma (CVE‑2026‑45586), and MiniPlasma (CVE‑2020‑17103). Several of those earlier flaws were exploited after exploit code became public but before patches were available, underlining how quickly local bugs can be folded into attack chains. Until Microsoft releases a patch, organizations should tighten local access, monitor for unusual Defender behavior, and prioritize endpoints exposed to untrusted users.

Patch Priority Checklist for Consumers and IT Teams
Given the mix of zero‑day vulnerabilities and critical flaws, patching should follow a clear order. For consumers, first apply Chrome security patches to reach at least version 149.0.7827.102, then apply the latest Windows updates and watch for a RoguePlanet fix. Disable or limit untrusted local accounts where possible. For IT and security teams, treat Ivanti Sentry’s CVSS 10.0 and 9.9 issues and Fortinet’s FortiSandbox command injection as top priorities, especially for internet‑facing systems. Next, review the CISA KEV catalog and patch Cisco SD‑WAN Manager and Chrome where applicable. For Arista EOS devices configured as tunnel endpoints, deploy vendor mitigations and validate tunnel policies since no patch is planned. Finally, build faster internal patch cycles so that when vendors and researchers report zero‑day vulnerabilities, you can close the active exploitation window before it becomes a major incident.







