CISA KEV: Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 (CVE-2026-85046)
CISA added actively exploited Chromium V8 type confusion CVE-2026-85046 to the KEV catalog, requiring federal mitigation by September 18.
CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium's V8 JavaScript engine, to the Known Exploited Vulnerabilities catalog. The flaw allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page and affects Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera. Federal agencies must apply vendor mitigations by 2026-09-18 under BOD 26-04; CISA notes known ransomware campaign use is currently unknown.
- Type confusion in V8 allows sandboxed arbitrary code execution via a crafted HTML page
- Affects all Chromium-based browsers: Chrome, Microsoft Edge, Opera, and others
- KEV listing mandates federal mitigation under BOD 26-04 with a 2026-09-18 due date
- Ransomware campaign use is listed as unknown
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85046 | Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046) Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references. Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints. | 8.8 | 1% | KEV PoC ×5 |
| massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus… |
Full article124 words · extracted from cisa.gov · click to collapse
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Search
Breadcrumb
- Home
- Known Exploited Vulnerabilities Catalog
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Learn more about how to use the KEV catalog in your organization.
Are you aware of an actively exploited vulnerability not included in the KEV Catalog?
NOMINATE A NEW KEV
The KEV catalog is also available in these formats:
CSVJSON Print View
JSON Schema (updated 06-25-2024)
License
Showing 1 to 20 of 1703 results
Cisco | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
CVE-2026-20079
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: Yes
- Date Added: 2026-09-09
- Due Date: 2026-09-12
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
Google | Chromium V8
CVE-2026-87491
Google Chromium V8 Out of Bounds Write Vulnerability: Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: No
- Date Added: 2026-09-09
- Due Date: 2026-09-23
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
Fortinet | Multiple Products
CVE-2025-25249
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability: Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: Yes
- Date Added: 2026-09-09
- Due Date: 2026-09-12
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
Citrix | NetScaler
CVE-2026-19490
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability: Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: Yes
- Date Added: 2026-09-09
- Due Date: 2026-09-12
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
Microsoft | Windows
CVE-2026-85880
Microsoft Windows Heap-Based Buffer Overflow Vulnerability: Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: No
- Date Added: 2026-09-08
- Due Date: 2026-09-22
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
N-able | N-central
CVE-2026-86218
N-able N-central Static Code Injection Vulnerability: N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: Yes
- Date Added: 2026-09-08
- Due Date: 2026-09-11
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
Microsoft | Windows
CVE-2026-81963
Microsoft Windows Link Following Vulnerability: Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: No
- Date Added: 2026-09-08
- Due Date: 2026-09-22
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
Adobe | Commerce and Magento
CVE-2026-75650
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability: Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: Yes
- Date Added: 2026-09-08
- Due Date: 2026-09-11
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
Google | Chromium V8
CVE-2026-85046
Google Chromium V8 Type Confusion Vulnerability: Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: No
- Date Added: 2026-09-04
- Due Date: 2026-09-18
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
SonicWall | SMA1000 Appliances
CVE-2026-83549
SonicWall SMA1000 Appliances OS Command Injection Vulnerability: SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: Yes
- Date Added: 2026-09-02
- Due Date: 2026-09-05
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
SonicWall | SMA1000 Appliances
CVE-2026-83548
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability: SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: Yes
- Date Added: 2026-09-02
- Due Date: 2026-09-05
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
Sangoma | Switchvox
CVE-2026-9586
Sangoma Switchvox SQL Injection Vulnerability: Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: Yes
- Date Added: 2026-09-02
- Due Date: 2026-09-05
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
JFrog | Artifactory
CVE-2026-82329
JFrog Artifactory Improper Authentication Vulnerability: JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: Yes
- Date Added: 2026-09-02
- Due Date: 2026-09-05
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
Kestra | Kestra OSS
CVE-2026-49869
Kestra OSS OS Command Injection Vulnerability: Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: Yes
- Date Added: 2026-09-02
- Due Date: 2026-09-05
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
Kludex | Starlette
CVE-2026-48710
Kludex Starlette HTTP Request/Response Smuggling Vulnerability: Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: No
- Date Added: 2026-09-02
- Due Date: 2026-09-16
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
BerriAI | LiteLLM
CVE-2026-59822
BerriAI LiteLLM Improper Authentication Vulnerability: BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: No
- Date Added: 2026-09-02
- Due Date: 2026-09-16
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
PaperCut | NG/MF
CVE-2026-81578
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability: PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: No
- Date Added: 2026-08-31
- Due Date: 2026-09-14
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
PaperCut | NG/MF
CVE-2026-82078
PaperCut NG/MF Unsafe Reflection Vulnerability: PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: No
- Date Added: 2026-08-31
- Due Date: 2026-09-14
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
JFrog | Artifactory
CVE-2026-66384
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability: JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: No
- Date Added: 2026-08-27
- Due Date: 2026-09-10
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
Linux | Kernel
CVE-2026-53362
Linux Kernel Unspecified Vulnerability: Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.
- Known To Be Used in Ransomware Campaigns? Unknown
- Forensic triage required per BOD-26-04: Yes
- Date Added: 2026-08-27
- Due Date: 2026-08-30
Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Additional Notes
- Currently on page 1
- Page 2
- Page 3
- Page 4
- Page 5
- Page 6
- Page 7
- Page 8
- Page 9
- …
- Go to next page
- Go to last page
Subscribe to the KEV Catalog Updates
Stay up to date on the latest known exploited vulnerabilities.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-85046