# Five Chrome Zero-Days in 2026: Why Forgotten Code Is Becoming Your Greatest Security Risk
## The Threat
Google shipped critical security patches for 74 vulnerabilities this week, including CVE-2026-11645, an out-of-bounds memory access in Chrome's V8 JavaScript engine that is already being exploited in the wild. This marks the fifth actively exploited Chrome zero-day since the start of 2026—a grim acceleration that signals attackers are keeping pace with browser security faster than patches can be deployed.
But the Chrome vulnerability tells only part of this week's story. Simultaneously, the ShinyHunters extortion gang (also tracked as UNC6240) was weaponizing CVE-2026-35273, an authentication bypass in Oracle PeopleSoft Enterprise that required zero user interaction. They exploited it to breach over 100 organizations, with 68% being universities and colleges. Meanwhile, hundreds of abandoned packages in the Arch Linux User Repository were silently modified to deploy a sophisticated rootkit and credential harvester called atomic-lockfile, turning the supply chain itself into a vector.
The pattern underlying this week is unmistakable: security failures are no longer concentrated in flashy zero-day discoveries. They're hiding in forgotten code—deprecated features still running in production, unmaintained packages nobody remembers downloading, authentication endpoints left behind during refactors, and infrastructure built years ago and then abandoned. These soft targets are easier to exploit, cheaper to weaponize, and reach organizations at scale because nobody is watching them.
## Severity and Impact
| Vulnerability | Product | CVE | CVSS Score | Vector | Actively Exploited | Key Detail |
|---|---|---|---|---|---|---|
| V8 Out-of-Bounds Memory Access | Google Chrome | CVE-2026-11645 | 8.8 | Network-based, Low Complexity | Yes (in the wild) | Affects all platforms; attackers avoid full disclosure to maximize patch window |
| Missing Authentication | Oracle PeopleSoft Enterprise PeopleTools | CVE-2026-35273 | 9.8 | Network-based, No Authentication Required | Yes (May 27–June 9) | 100+ organizations breached; primarily higher education; data published to leak site |
| Abandoned Package Compromise | Arch Linux User Repository | N/A (supply chain) | Critical | Local execution upon install | Yes (ongoing) | 1,500+ packages modified; atomic-lockfile payload includes credential harvesting, anti-debugging, data exfiltration |
## Affected Products
Google Chrome & Chromium-Based Browsers
Oracle PeopleSoft
Arch Linux & AUR
## Mitigations
For Chrome Users & Administrators
For Oracle PeopleSoft Deployments
For Arch Linux Users & Developers
Supply Chain Defense (All Organizations)
## References
---
## HackWire Analysis
The number that should alarm you: five Chrome zero-days in six months. This isn't an anomaly—it's the new baseline. Browser engines have become so complex that the attack surface grows faster than the patch cycle. But what's more dangerous is what this week reveals about infrastructure decay.
The real vulnerability isn't CVE-2026-11645. It's that organizations are still running authentication systems built in 2015, still have forgotten endpoints listening on internal networks, and still trust that "nobody uses this anymore" means "nobody can exploit it." The Arch Linux compromise demonstrates how this works at scale: 1,500 packages modified because nobody was maintaining them, nobody was verifying them, and nobody was watching. That's not a supply chain attack—that's grave robbing.
Universities and colleges made up 68% of the PeopleSoft victims. Why? Because student information systems are often deployed once and then forgotten. They're patched slowly, monitored loosely, and isolated just enough that they feel safe. That's the profile ShinyHunters hunts for: critical systems running old code with minimal visibility.
The lesson for defenders is unsettling: the majority of your exploitable surface isn't in your latest projects. It's in the infrastructure you stopped thinking about three years ago. Start an audit this week. Find every package, every service, every authentication path that hasn't been touched in 12 months. That's your real threat surface. The zero-day exploits are just reminders.
— HackWire Editorial
## Related Coverage