CISA Adds One Known Exploited Vulnerability to Catalog
Summary
CISA has added CVE-2026-85046, a Google Chromium V8 type confusion vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This action reinforces Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize the remediation of such high-risk vulnerabilities on publicly exposed assets.
IFF Assessment
The addition of a new, actively exploited vulnerability to CISA's KEV catalog indicates a new threat vector that defenders must address promptly.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 18, 2026. Known ransomware use: Unknown.
Defender Context
The inclusion of CVE-2026-85046 in CISA's KEV catalog highlights the ongoing threat posed by actively exploited vulnerabilities in widely used software like Google Chromium. Defenders should prioritize patching this vulnerability, especially on publicly facing systems, to mitigate the risk of compromise and adhere to federal operational directives.