CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA Adds One Known Exploited Vulnerability to Catalog

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5727

As cited

Copy frozen at (site build).

vulnerabilities

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8, to its Known Exploited Vulnerabilities Catalog on September 4, 2026. The vulnerability enables total asset control upon exploitation and affects federal civilian agencies covered by Binding Operational Directive 26-04, which mandates rapid remediation of high-risk vulnerabilities on publicly exposed systems.

Why it matters: Federal agencies must prioritize patching this vulnerability on exposed assets; all organizations should adopt similar risk-based remediation practices for KEV Catalog entries.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2026-85046, a Google Chromium V8 type confusion vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence. The vulnerability carries a CVSS score of 8.8 and is subject to Binding Operational Directive (BOD) 26-04, which requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk KEV Catalog vulnerabilities on publicly exposed assets.

Why it matters: Federal agencies must immediately prioritize patching CVE-2026-85046 on exposed systems per BOD 26-04; all organizations should treat this type confusion bug as high priority given the CVSS 8.8 score and active exploitation in the wild.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds One Known Exploited Vulnerability to Catalog

CISA added CVE-2026-85046, a Google Chromium V8 type confusion vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence. The vulnerability carries a CVSS score of 8.8 and is subject to Binding Operational Directive (BOD) 26-04, which requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk KEV Catalog vulnerabilities on publicly exposed assets.

Why it matters: Federal agencies must immediately prioritize patching CVE-2026-85046 on exposed systems per BOD 26-04; all organizations should treat this type confusion bug as high priority given the CVSS 8.8 score and active exploitation in the wild.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary