CISA adds Chromium V8 flaw to KEV list
CISA added an actively exploited Chromium V8 type confusion vulnerability (CVE-2026-85046) to its Known Exploited Vulnerabilities catalog, requiring federal agencies to remediate per BOD 26-04.
CISA has added CVE-2026-85046, a type confusion vulnerability in Google Chromium's V8 JavaScript engine, to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation. Type confusion bugs in V8 are a recurring class of vulnerability that attackers leverage for remote code execution or sandbox escape in Chromium-based browsers, making them a frequent vector for both targeted and opportunistic campaigns.
Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of vulnerabilities in the KEV Catalog, particularly those on publicly exposed assets that could grant an attacker full control post-exploitation. The directive also mandates that agencies check whether systems were compromised prior to patching. While the directive is binding only on FCEB agencies, CISA recommends that all organizations adopt similar risk-based vulnerability management practices and treat KEV Catalog entries as high priority for patching.
No further technical details, exploitation actors, or malware associated with this activity were disclosed in the advisory. Organizations running Chromium-based browsers (Chrome, Edge, and derivatives) should verify they are on patched versions and monitor for indicators of compromise consistent with browser exploitation.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/04/cisa-adds-one-known-exploited-vulnerability-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free