PAN-SA-2026-0011 Chromium: Monthly Vulnerability Update (August 2026) (Severity: HIGH)
CSIRTS triage
- What
- Multiple vulnerabilities patched in Chromium as part of the August 2026 monthly security update.
- Who is affected
- Organizations and users running Chromium-based browsers in August 2026.
- Urgency
- High urgency due to high severity rating and potential for remote code execution via web content.
- Action
- Update Chromium to the patched version released for August 2026.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chromium
Get an email when a new Chromium advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://security.paloaltonetworks.com/PAN-SA-2026-0011
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-137740.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137750.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137760.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137770.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137780.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137790.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137800.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137810.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137820.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-137830.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Palo Alto Networks products (August 13, 2026)cert-fr-avis
- high[UPDATE] [high] Google Chrome: Multiple vulnerabilities allow unspecified attackcert-bund
- unknownMultiple vulnerabilities in Microsoft Edge (July 15, 2026)cert-fr-avis
- unknownCVE-2026-13782: Chromium: CVE-2026-13782 Use after free in Browsermsrc
- unknownCVE-2026-13829: Chromium: CVE-2026-13829 Insufficient validation of untrusted input in Settingsmsrc
- unknownCVE-2026-13811: Chromium: CVE-2026-13811 Use after free in IMEmsrc
- unknownCVE-2026-13776: Chromium: CVE-2026-13776 Type Confusion in Dawnmsrc
- unknownCVE-2026-13783: Chromium: CVE-2026-13783 Use after free in Viewsmsrc
- unknownCVE-2026-13787: Chromium: CVE-2026-13787 Use after free in Chromotingmsrc
- unknownCVE-2026-13823: Chromium: CVE-2026-13823 Use after free in Glicmsrc
- unknownCVE-2026-13817: Chromium: CVE-2026-13817 Insufficient validation of untrusted input in Glicmsrc
- unknownCVE-2026-13780: Chromium: CVE-2026-13780 Insufficient validation of untrusted input in ANGLEmsrc
More from Palo Alto Networks Security Advisories
- mediumCVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake (Severity: MEDIUM)2026-08-12
- mediumCVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS (Severity: MEDIUM)2026-08-12
- lowCVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering (Severity: LOW)2026-08-12
- mediumCVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)2026-08-12
- mediumCVE-2026-0294 Prisma Access Agent: Local Privilege Escalation (Severity: MEDIUM)2026-08-12