- As of Sept. 9, Chrome users should be running: Chrome 153.0.8010.36/.37 on Windows and macOS, Chrome 153.0.8010.36 on Linux, and Chrome 153.0.8010.36 on Android.
- Microsoft has announced fixes for a record 974 CVEs in its September 2026 Patch Tuesday release, shattering the previous record set in July 2026.
- Microsoft's September 2026 Patch Tuesday release addresses 974 vulnerabilities across Windows and Microsoft enterprise products, including 114 Critical flaws.
- The jump in CVEs follows a warning by Microsoft to customers in July to expect a surge in security updates due to its tools to discover zero-day vulnerabilities.
- As part of its September 8 release, Microsoft highlighted two zero-day flaws actively exploited: a heap-based buffer overflow in Windows ALPC (severity 7.8) and an improper link resolution in Windows Update Stack, both allowing local privilege escalation.
Google's Chrome 153 has been released with critical security updates, including a fix for CVE-2026-87491, an actively exploited vulnerability in the V8 JavaScript engine. Users are urged to update promptly to mitigate risks from potential cyberattacks.
The update addresses a total of 230 security fixes across platforms including Windows, macOS, Linux, and Android. Google emphasizes the importance of timely updates, stating, “Even if you don't consider yourself a high-risk target, installing security updates promptly is one of the easiest ways to reduce your exposure to cyberattacks.”

In parallel, Microsoft's September Patch Tuesday has set a new record with 974 CVEs, surpassing previous months significantly. This includes 114 critical vulnerabilities affecting various products such as Windows, Office, and Azure. The surge in vulnerabilities patched this month follows a warning from Microsoft about an expected increase in security updates due to enhanced vulnerability discovery tools.

Jack Bicer, director of vulnerability research at Action1, noted, “At this scale, the challenge is not simply getting through the patch list. It is knowing what needs attention first.” The update highlights the need for organizations to adopt a risk-based approach to vulnerability management, prioritizing the most critical flaws.
As cyber threats evolve, both Google and Microsoft stress the importance of maintaining updated software to protect against exploitation.
“The Chrome zero-day, tracked as CVE-2026-87491, does not affect iOS, but Android users should update via Google Play. Microsoft's record-breaking update includes fixes for 114 Critical flaws, with Windows affected by 723 CVEs, and two actively exploited zero-days in Windows ALPC and Windows Update Stack.”











