The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added one vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The newly added flaw is CVE-2026-85046, a Google Chromium V8 type confusion vulnerability. CISA notes that this vulnerability type is a frequent attack vector for malicious actors and poses significant risks to federal enterprise systems.
The addition, announced on September 4, 2026, comes under Binding Operational Directive (BOD) 26-04, which establishes vulnerability management requirements for federal civilian executive branch (FCEB) agencies. The directive requires agencies to prioritize remediation of high-risk KEV vulnerabilities. CISA says it will continue adding vulnerabilities that meet its specified criteria to the catalog.
The announcement does not specify a patch deadline for CVE-2026-85046, nor does it list affected products or versions. CISA did not release technical details, a severity score, or any attribution to a threat actor.
CISA encourages submission of exploited vulnerabilities through its KEV Nomination Form, which requires a CVE ID, evidence of exploitation, and mitigation guidance.
This addition follows a series of recent updates to the KEV catalog. On September 2, 2026, CISA added seven vulnerabilities. On August 31, 2026, it added two PaperCut vulnerabilities. Earlier, in December 2025, CISA warned about an Apple WebKit vulnerability (CVE-2025-43529) that was added to the KEV catalog on December 16, with a patch deadline of January 5, 2026. Apple released emergency updates on December 12, describing the attacks as "extremely sophisticated" in its support documentation.
The WebKit flaw, a use-after-free issue, could allow attackers to trigger arbitrary code execution via web content, affecting iOS, iPadOS, macOS, and other Apple platforms. Google patched a related Chrome vulnerability (CVE-2025-14174), and the two companies jointly discovered the memory corruption issue. WebKit powers Safari and underpins browsing across the Apple ecosystem, and apps from other developers that rely on WebKit faced potential exposure as well.
The directive covers FCEB agencies only, but CISA says organizations outside the federal government should also treat catalog listings as a patching priority.













