official data

CISA KEV: Chromium V8 type confusion CVE-2026-85046 added — active exploitation

Origin Lane: ai

On 4 September 2026, CISA published an alert stating it added one vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability. CISA’s KEV catalog entry (Date Added 2026-09-04; Due Date 2026-09-18) describes a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page and notes it could affect multiple Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera. Related CWE listed: CWE-843. Known ransomware campaigns: Unknown. Forensic triage required per BOD-26-04: No. The alert cites BOD 26-04 risk-based remediation requirements for FCEB agencies and encourages all organizations to prioritize KEV remediation.

Key facts

Alert date
September 4, 2026 — one CVE added to KEV Catalog
CVE
CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability
KEV dates
Date Added 2026-09-04; Due Date 2026-09-18
CWE
CWE-843
Ransomware / forensic triage
Known ransomware campaigns: Unknown; Forensic triage required per BOD-26-04: No
Policy hook
BOD 26-04 risk-based KEV remediation for FCEB; CISA encourages all organizations to prioritize KEV remediation

Note

Official product: CISA alert dated 4 September 2026 plus the KEV Catalog listing for CVE-2026-85046. Doom Signals does not invent exploit prevalence, victim counts, or autonomous-AI-attacker claims beyond CISA’s “evidence of active exploitation” framing for catalog inclusion.

BOD 26-04 applies to Federal Civilian Executive Branch agencies; CISA encourages others. This is not a private-sector mandatory deadline beyond that framing.

  • Source: CISA KEV alert, 4 Sep 2026
  • Catalog add: CVE-2026-85046 Chromium V8 type confusion
  • GEO: omitted — catalog add, no real place pin
  • Dedup: not Sep 2 LiteLLM/SonicWall seven-CVE KEV drop

Why it matters

Same-day KEV add on the Chromium V8 engine is a concrete AI/browser-attack-surface governance signal (active exploitation evidence, federal due date). Distinct from the Sep 2 LiteLLM/SonicWall seven-CVE KEV drop already boarded. Victim counts and in-the-wild exploit detail beyond CISA’s “evidence of active exploitation” framing are not invented here.

Sources

Official data. Not a forecast.

← Daily board