WatchGuard Ransomware Exploitation and Chrome Zero-Day Chain Target UK SMBs

WatchGuard Ransomware Exploitation and Chrome Zero-Day Chain Target UK SMBs

•

Episode description

WatchGuard Ransomware Exploitation and Chrome Zero-Day Chain Target UK SMBs

Two active exploitation campaigns are affecting UK small businesses today. Ransomware operators are exploiting a critical WatchGuard Firebox vulnerability that was added to CISA’s Known Exploited Vulnerabilities catalogue in December 2025, yet remains unpatched in many deployments nine months later. The flaw allows remote, unauthenticated code execution on internet-facing devices. Separately, four China-aligned threat actors have adopted an identical Chrome and Windows zero-day exploit chain within days of each other, enabling full system compromise through a single malicious webpage visit. The BlueMoon exploit kit combines CVE-2026-85046 in Chrome’s V8 engine with CVE-2026-85880 in the Windows kernel. Patches are available for both campaigns. Additionally, Cisco Secure Firewall Management Center is under active exploitation via two vulnerabilities that grant administrative control, with possible connections to the Qilin ransomware group. Today’s briefing provides specific remediation steps for each threat and examines why a nine-month-old vulnerability continues to find victims, highlighting fundamental patch management failures across the UK SMB sector. Mauven frames the discussion around visibility, accountability, and the compression of exploitation windows in modern threat environments.

Chapters

  • Introduction Mauven opens the tenth of September 2026 briefing with two active exploitation events affecting UK small businesses: a nine-month-old WatchGuard vulnerability now used by ransomware operators, and a browser-based zero-day chain adopted by four state-aligned actors within days.
  • WatchGuard Firebox Ransomware Exploitation CISA confirms ransomware gangs are actively exploiting a critical remote code execution flaw in WatchGuard Firebox appliances. The vulnerability was added to the KEV catalogue in December 2025, yet remains unpatched in many UK SMB deployments. Ransomware operators use automated scanning to find vulnerable devices. Mauven emphasises the need to verify firmware versions immediately and obtain written confirmation from managed service providers.
  • Call to Action Mauven encourages listeners to follow the show and share it with colleagues who need daily threat intelligence.
  • BlueMoon Chrome Zero-Day Exploit Chain Proofpoint and Volexity report on the BlueMoon exploit kit, which chains CVE-2026-85046 in Chrome’s V8 engine with CVE-2026-85880 in the Windows kernel. Four China-aligned threat actors adopted identical exploitation within days, suggesting coordinated or brokered tooling. The attack requires only visiting a compromised webpage and achieves full system compromise. Patches are available from Google and Microsoft’s September 2026 Patch Tuesday.
  • Cisco Secure Firewall Management Center Exploitation Cisco Talos tracks active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center, which together grant administrative control. Possible connections to the Qilin ransomware group are noted. The vulnerability primarily affects mid-market professional services and managed security provider infrastructure.
  • Patch Management Reality Check Mauven examines the operational reality of three network security products under active exploitation in the same news cycle. The continued exploitation of a nine-month-old WatchGuard vulnerability demonstrates that patch management is treated as optional despite NCSC guidance. The core issue is visibility: organisations must be able to answer which internet-facing devices and applications were updated in the last thirty days.
  • Closing and Practical Takeaway Mauven summarises the immediate action items: confirm WatchGuard Firebox firmware is current and verify Chrome and Windows updates are applied across all devices. Listeners are encouraged to demand specific answers from IT providers, not vague reassurances.

Links