ZeroHour
CISA Known Exploited Vulnerabilitiespublished ()ingested

CISA KEV: Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 (CVE-2026-85046)

highExploit / PoC exploited in the wildimportance 85CVE-2026-85046
AI summary · glm-5.3-flash

CISA added actively exploited Chromium V8 type confusion CVE-2026-85046 to the KEV catalog, requiring federal mitigation by September 18.

CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium's V8 JavaScript engine, to the Known Exploited Vulnerabilities catalog. The flaw allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page and affects Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera. Federal agencies must apply vendor mitigations by 2026-09-18 under BOD 26-04; CISA notes known ransomware campaign use is currently unknown.

  • Type confusion in V8 allows sandboxed arbitrary code execution via a crafted HTML page
  • Affects all Chromium-based browsers: Chrome, Microsoft Edge, Opera, and others
  • KEV listing mandates federal mitigation under BOD 26-04 with a 2026-09-18 due date
  • Ransomware campaign use is listed as unknown
VendorsGoogleCISA
ProductsChromiumV8
OrganizationsGoogleCISA

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-85046
Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)

Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references.

Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints.

8.81% KEV PoC ×5
  • Google Chrome prior to 152.0.7977.82
  • Google Chromium V8 V8 engine versions bundled with Chrome prior to 152.0.7977.82
massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus…
Full article124 words · extracted from cisa.gov · click to collapse

U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search

Breadcrumb

  1. Home
  2. Known Exploited Vulnerabilities Catalog

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Learn more about how to use the KEV catalog in your organization.

Are you aware of an actively exploited vulnerability not included in the KEV Catalog?
NOMINATE A NEW KEV

The KEV catalog is also available in these formats:
CSVJSON Print View
JSON Schema (updated 06-25-2024)
License


Showing 1 to 20 of 1703 results

Cisco | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

CVE-2026-20079

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  Yes
  • Date Added:  2026-09-09
  • Due Date:  2026-09-12

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Google | Chromium V8

CVE-2026-87491

Google Chromium V8 Out of Bounds Write Vulnerability: Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  No
  • Date Added:  2026-09-09
  • Due Date:  2026-09-23

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Fortinet | Multiple Products

CVE-2025-25249

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability: Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  Yes
  • Date Added:  2026-09-09
  • Due Date:  2026-09-12

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Citrix | NetScaler

CVE-2026-19490

Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability: Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  Yes
  • Date Added:  2026-09-09
  • Due Date:  2026-09-12

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Microsoft | Windows

CVE-2026-85880

Microsoft Windows Heap-Based Buffer Overflow Vulnerability: Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  No
  • Date Added:  2026-09-08
  • Due Date:  2026-09-22

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

N-able | N-central

CVE-2026-86218

N-able N-central Static Code Injection Vulnerability: N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  Yes
  • Date Added:  2026-09-08
  • Due Date:  2026-09-11

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Microsoft | Windows

CVE-2026-81963

Microsoft Windows Link Following Vulnerability: Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  No
  • Date Added:  2026-09-08
  • Due Date:  2026-09-22

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Adobe | Commerce and Magento

CVE-2026-75650

Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability: Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  Yes
  • Date Added:  2026-09-08
  • Due Date:  2026-09-11

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Google | Chromium V8

CVE-2026-85046

Google Chromium V8 Type Confusion Vulnerability: Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  No
  • Date Added:  2026-09-04
  • Due Date:  2026-09-18

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

SonicWall | SMA1000 Appliances

CVE-2026-83549

SonicWall SMA1000 Appliances OS Command Injection Vulnerability: SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  Yes
  • Date Added:  2026-09-02
  • Due Date:  2026-09-05

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

SonicWall | SMA1000 Appliances

CVE-2026-83548

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability: SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  Yes
  • Date Added:  2026-09-02
  • Due Date:  2026-09-05

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Sangoma | Switchvox

CVE-2026-9586

Sangoma Switchvox SQL Injection Vulnerability: Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  Yes
  • Date Added:  2026-09-02
  • Due Date:  2026-09-05

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

JFrog | Artifactory

CVE-2026-82329

JFrog Artifactory Improper Authentication Vulnerability: JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  Yes
  • Date Added:  2026-09-02
  • Due Date:  2026-09-05

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Kestra | Kestra OSS

CVE-2026-49869

Kestra OSS OS Command Injection Vulnerability: Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  Yes
  • Date Added:  2026-09-02
  • Due Date:  2026-09-05

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Kludex | Starlette

CVE-2026-48710

Kludex Starlette HTTP Request/Response Smuggling Vulnerability: Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  No
  • Date Added:  2026-09-02
  • Due Date:  2026-09-16

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

BerriAI | LiteLLM

CVE-2026-59822

BerriAI LiteLLM Improper Authentication Vulnerability: BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  No
  • Date Added:  2026-09-02
  • Due Date:  2026-09-16

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

PaperCut | NG/MF

CVE-2026-81578

PaperCut NG/MF Missing Authentication for Critical Function Vulnerability: PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  No
  • Date Added:  2026-08-31
  • Due Date:  2026-09-14

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

PaperCut | NG/MF

CVE-2026-82078

PaperCut NG/MF Unsafe Reflection Vulnerability: PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  No
  • Date Added:  2026-08-31
  • Due Date:  2026-09-14

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

JFrog | Artifactory

CVE-2026-66384

JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability: JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  No
  • Date Added:  2026-08-27
  • Due Date:  2026-09-10

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Linux | Kernel

CVE-2026-53362

Linux Kernel Unspecified Vulnerability: Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

  • Known To Be Used in Ransomware Campaigns? Unknown
  • Forensic triage required per BOD-26-04:  Yes
  • Date Added:  2026-08-27
  • Due Date:  2026-08-30

Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Additional Notes

Subscribe to the KEV Catalog Updates

Stay up to date on the latest known exploited vulnerabilities.

Subscribe Now

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-85046