CISA adds CVE-2026-85046 to the Known Exploited Vulnerabilities Catalog

BRIEF
CVE-2026-85046, described as a Google Chromium V8 type-confusion vulnerability, has been added to the Known Exploited Vulnerabilities Catalog. The catalog entry is the key operational fact: evidence exists that malicious actors are exploiting the flaw. The supplied material does not provide affected browser versions, exploit details, vendor patch information, or a remediation deadline for non-federal organizations. It does state that the vulnerability class is a frequent attack vector and that the flaw can pose significant risk to federal systems. A federal directive requires civilian executive-branch agencies to prioritize certain catalog vulnerabilities on publicly exposed assets that could grant total control after exploitation, and to consider whether compromise occurred before remediation. Those requirements do not automatically apply to private organizations, but the risk signal is broadly useful. Enterprises should identify Chromium-based browsers and embedded Chromium components, confirm vendor guidance, deploy the relevant fix when available, and verify that updates reached managed and unmanaged endpoints. Because active exploitation is confirmed, patching should be paired with review of browser, endpoint, identity, and network telemetry for suspicious activity before the update. Do not infer compromise solely from exposure, and do not assume a browser restart proves complete remediation.
WHY IT MATTERS
A KEV listing changes the priority of vulnerability management because exploitation is no longer merely theoretical. Browsers are widely deployed and often handle credentials, business applications, and sensitive data, so an exploitable client can become an entry point even when perimeter controls remain intact. The supplied facts do not establish the affected versions or the attacker’s technique, which means teams must use vendor-specific guidance rather than guesswork. Remediation should include asset discovery, update verification, and a proportionate check for signs of compromise. Federal obligations are specific, but the underlying risk-based practice is relevant to other organizations.