PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) (Severity: HIGH)
Details
Original advisory: https://security.paloaltonetworks.com/PAN-SA-2026-0012
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-760200.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760220.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760380.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760460.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-760470.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-790160.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-790320.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-791180.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-791950.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-792820.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Google Chrome: Mehrere Schwachstellencert-bund
- unknownCVE-2026-84350: Chromium: CVE-2026-84350 Use after free in TabStripmsrc
- unknownCVE-2026-84357: Chromium: CVE-2026-84357 Improper input validation in Omniboxmsrc
- unknownCVE-2026-84359: Chromium: CVE-2026-84359 Information leak in Skiamsrc
- unknownCVE-2026-84351: Chromium: CVE-2026-84351 Buffer overflow in GPUmsrc
- unknownCVE-2026-84348: Chromium: CVE-2026-84348 Information leak in MediaCapturemsrc
- unknownCVE-2026-84358: Chromium: CVE-2026-84358 Improper privilege management in Downloadsmsrc
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- unknownMultiples vulnérabilités dans Microsoft Edge (04 septembre 2026)cert-fr-avis
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- lowCVE-2026-84359: Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who…nvd
- mediumCVE-2026-84358: Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a r…nvd
More from Palo Alto Networks Security Advisories
- mediumCVE-2026-0306 Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows (Severity: MEDIUM)2026-09-09
- lowCVE-2026-0303 Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File (Severity: LOW)2026-09-09
- lowCVE-2026-0302 Checkov by Prisma Cloud: OS Command Injection Vulnerability (Severity: LOW)2026-09-09
- mediumCVE-2026-0305 Prisma Access Agent: Information Disclosure Vulnerability on Linux (Severity: MEDIUM)2026-09-09
- highCVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing (Severity: HIGH)2026-09-09