Cybersecurity Bulletin

Google Chrome & SAP Vulnerabilities, Cyberattacks & Major Data Breaches                            7–20 September 2026

Reading Time: 3 Minutes
9/22/2026
Google Chrome & SAP Vulnerabilities

The global cybersecurity landscape continues to evolve as organizations face critical software vulnerabilities, data breaches, cyber-espionage campaigns, supply chain attacks, and operational disruption. Recent developments involving Google Chrome, SAP, West Publishing / C-Track, Florida DMV, Luminis Health, Veradigm, Trezor, Brevo, and CenterPoint Energy reinforce the importance of proactive vulnerability management, threat monitoring, third-party risk management, and incident response.

Google Chrome and SAP Vulnerabilities Require Attention

Several vulnerabilities affecting Google Chrome and SAP environments have emerged as important security concerns. Google Chrome vulnerabilities include CVE-2026-87464, a WebGL use-after-free vulnerability; CVE-2026-91728, an integer overflow vulnerability affecting V8; CVE-2026-91721, a use-after-free vulnerability involving Chrome Internals; and CVE-2026-91749, a use-after-free vulnerability affecting Chrome Workers.

SAP-related security issues include CVE-2026-44756, involving memory corruption in SAP Extended Passport (EPP) processing, and CVE-2026-58240, involving a missing authentication check in the SAP NetWeaver Message Server.

Organizations should assess affected environments, review applicable vendor security advisories, and implement relevant patches or mitigations. Timely vulnerability remediation and continuous monitoring can help reduce exposure to potential exploitation.

Cyberattack Campaigns Highlight Data Theft and Operational Risks

Recent attack campaigns demonstrate the diverse techniques used by threat actors. The West Publishing / C-Track court-system data breach highlights risks affecting judicial technology environments, while an AI-assisted Russian cyber-espionage campaign involving Anthropic demonstrates the growing intersection between artificial intelligence and cyber operations.

Other developments include the Florida DMV driver database breach, unauthorized access and data exfiltration involving FiveWest, and a cyberattack affecting Luminis Health and disrupting healthcare systems. The disruption of NightmareStresser, a global DDoS-for-hire infrastructure, also reflects continuing efforts to combat cybercrime operations.

Third-Party and Supply Chain Cybersecurity Risks

Third-party security remains a significant concern. Recent incidents involving Veradigm, Surfshark, Trezor, CenterPoint Energy, and Brevo highlight risks including data theft, phishing, compromised servers, and supply chain attacks. The Brevo ClickFix supply chain attack demonstrates how trusted technology providers can become attack vectors, while Spain’s reported personal data breach involving an AI agent highlights emerging risks associated with AI-enabled systems.

For organizations across the UAE, Middle East, and global markets, these developments reinforce the need to strengthen cyber risk management, vulnerability remediation, third-party security, identity and access controls, threat monitoring, and incident-response capabilities.

Staying informed about Google Chrome vulnerabilities, SAP vulnerabilities, data breaches, cyberattacks, supply chain threats, and global cybersecurity trends can help organizations identify emerging risks and strengthen cyber resilience.

For Cybersecurity and Cyber Threat Management consulting:

Call / WhatsApp: +971 52 373 4662 | Email: [email protected]

Dawn Thomas
Dawn Thomas
Senior Partner - Governance Risk & Compliance
shahnawaz.sheik@crowe.ae
Shahnawaz Sheik
Director – Cyber Threat Management