Chrome Zero-Day and WordPress Under Fire: What UK Small Businesses Must Do Right Now

Podcast

Chrome Zero-Day and WordPress Under Fire: What UK Small Businesses Must Do Right Now

Two active exploits landed on the same day. One targets the browser sitting open on every desk in your business. The other targets the website your customers trust with their data. Both have patches. The question is whether you apply them before an attacker gets there first.

This is the 4th September 2026 threat briefing.

Story One: Your Browser Is Being Exploited Right Now

CVE-2026-85046 is a type confusion vulnerability in V8, the JavaScript engine inside Google Chrome, Microsoft Edge, Opera, and every other Chromium-based browser. CISA added it to its Known Exploited Vulnerabilities catalogue today, which means this is not theoretical: attackers are actively using it against real targets.

The mechanism is straightforward and, frankly, unpleasant. An attacker crafts a malicious webpage. A user visits it. Code executes inside the browser sandbox. No download prompt. No warning. Just a webpage and a compromised session.

Google has already shipped the fix in an updated version of Chrome. The problem is that Chrome only applies updates when it is restarted. If your staff leave Chrome running for days without closing it, which most do, they are running the vulnerable version right now, regardless of automatic update settings.

This affects every business that uses a Chromium-based browser. Which is most of them.

The fix takes thirty seconds. Restart Chrome. On every device. Today.

If your business uses Microsoft Edge, the same Chromium engine is underneath it. Check for and apply Edge updates as well. Microsoft typically follows Google’s patches rapidly, but verify rather than assume.

One further point worth making to anyone who manages others: do not send a group email asking staff to restart their browsers and assume it will happen. Walk around. Confirm it. The gap between “we told everyone” and “everyone did it” is where incidents live.

Story Two: WordPress Sites Are Under Mass Attack

While the Chrome story is the highest-priority item today, the WordPress situation deserves equal attention from any business running a website on that platform.

Wordfence has documented over 440,000 exploit attempts targeting two vulnerabilities: one in the Super Forms plugin (CVE-2026-14894) and one in Elementor Pro (CVE-2026-32475). Both allow attackers to upload PHP files and execute arbitrary code on the web server. In plain terms: a successful attack gives an attacker control of your website.

Elementor Pro is one of the most widely used WordPress page-builder plugins in existence. If your website was built by a designer or developer in the last five years, there is a meaningful probability it is installed.

The scale of 440,000 attempts matters here. This is not targeted. These are automated scanners hitting every WordPress site they can find, probing for unpatched versions. Small businesses are not being singled out; they are simply in the pool. Being small does not protect you. It just means you are less likely to have someone watching.

A compromised WordPress site is not merely a reputational problem. Attackers use compromised sites to host phishing pages, distribute malware to your customers, exfiltrate contact form data, and as launchpads into whatever internal systems your site connects to. If your site has a contact form that feeds into a CRM, that connection is now a risk vector.

The fix: log into your WordPress admin panel and update every plugin. If you do not have admin access to your own website, that is a separate problem worth addressing, but start by calling whoever manages it and confirming these updates have been applied.

If you use a managed hosting provider or a web developer on retainer, ask them directly: have CVE-2026-14894 and CVE-2026-32475 been patched? If they cannot answer that question clearly, that tells you something about the quality of the service you are receiving.

The Pattern Behind Both Stories

These two stories share a structural problem that shows up consistently in incident data: the gap between a patch being available and a patch being applied.

Google shipped the Chrome fix. The WordPress plugin vendors shipped their fixes. The vulnerability information is public. The exploits are automated. Attackers are, by definition, faster than most patch management processes.

For small businesses, the honest truth is that patch management is often informal or nonexistent. Updates happen when someone notices them, or when something breaks. That approach is no longer adequate when CISA is adding vulnerabilities to its actively-exploited list on the same day they become public knowledge.

This is not an argument for buying an expensive patch management platform. It is an argument for treating software updates as a routine operational task, the same way you would treat a boiler service or a fire alarm test. Not exciting. Not optional.

If you have an MSP managing your IT, ask them today: what is your patching SLA for CISA KEV items? If they do not have an answer, you have a gap in your service agreement worth closing.

How This Gives You an Edge

Clients and prospects increasingly ask about security practices during procurement, particularly in sectors handling personal data. Being able to demonstrate that your business responds to active threat intelligence within hours rather than weeks is a concrete, verifiable signal.

It does not require certification. It does not require a security team. It requires a process: monitor for critical updates, apply them promptly, document that you did so.

That documentation matters. If you ever face a GDPR inquiry or an insurance claim following an incident, being able to show that you applied a patch within the day CISA flagged it as actively exploited is a substantially different position than being unable to show when you last updated your plugins.

Making the Case to Your Board or Budget Holder

Three arguments that land:

The cost of inaction is asymmetric. Restarting Chrome costs thirty seconds per device. A website compromise can cost days of downtime, customer notification obligations under UK GDPR, and ICO scrutiny. The comparison is not even close.

Automated attacks do not discriminate by company size. The 440,000 WordPress exploit attempts are not targeting large enterprises. They are scanning everything. Your size is not a defence.

Regulatory exposure is real. A breach resulting from a known, patched vulnerability, where evidence shows the patch was not applied, is a difficult position to defend to the ICO. Applying available patches promptly is one of the clearest demonstrations of the “appropriate technical measures” required under UK GDPR Article 32.

What to Do Before the End of Today

  1. Restart Chrome on every device in your business. Check that the version updates. On Chrome desktop, go to the three-dot menu, Help, then About Google Chrome. If it starts downloading an update, let it finish and restart again. If your business uses Edge, do the same via Settings, Help and Feedback, then About Microsoft Edge.

  2. Log into your WordPress admin panel and update all plugins. Go to Dashboard, then Updates. Apply everything available, not just the two affected plugins. If you cannot log in, contact whoever manages your site today, not at their convenience.

  3. Ask your MSP or IT provider what their patching process is for CISA KEV items. A reasonable expectation is that critical actively-exploited vulnerabilities are patched within 24 to 48 hours. If they cannot confirm this, you need a conversation about your service level.

  4. Check your other Chromium-based browsers. If staff use Brave, Opera, or other Chromium derivatives, those need updating too. The underlying engine is the same.

  5. Document what you did and when. A quick note in a shared document, an email to yourself, anything that creates a timestamped record. It costs nothing and it matters if you ever need to demonstrate due diligence.

Before you go: follow the show wherever you listen, leave a rating or review, drop a comment with your thoughts, and share this episode with someone who would find it useful. The more people acting on this kind of intelligence today, the fewer incidents to talk about next week.

SourceArticle
CISAKnown Exploited Vulnerabilities Catalogue: CVE-2026-85046
The Hacker NewsGoogle Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
The Hacker NewsOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
NIST NVDCVE-2026-85046: Chromium V8 Type Confusion Vulnerability
NIST NVDCVE-2026-11613: Divi Ajax Filter WordPress Plugin Local File Inclusion
NCSCVulnerability Management: Guidance for Organisations
ICOSecurity under UK GDPR: Article 32 Appropriate Technical Measures

Filed under

  • smb-security
  • uk-business
  • ransomware-groups
  • compliance-failure
  • business-risk
  • vendor-risk
  • incident-response