official data
CISA KEV: Chromium V8 type confusion CVE-2026-85046 added — active exploitation
On 4 September 2026, CISA published an alert stating it added one vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability. CISA’s KEV catalog entry (Date Added 2026-09-04; Due Date 2026-09-18) describes a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page and notes it could affect multiple Chromium-based browsers including Google Chrome, Microsoft Edge, and Opera. Related CWE listed: CWE-843. Known ransomware campaigns: Unknown. Forensic triage required per BOD-26-04: No. The alert cites BOD 26-04 risk-based remediation requirements for FCEB agencies and encourages all organizations to prioritize KEV remediation.
Key facts
- Alert date
- September 4, 2026 — one CVE added to KEV Catalog
- CVE
- CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability
- KEV dates
- Date Added 2026-09-04; Due Date 2026-09-18
- CWE
- CWE-843
- Ransomware / forensic triage
- Known ransomware campaigns: Unknown; Forensic triage required per BOD-26-04: No
- Policy hook
- BOD 26-04 risk-based KEV remediation for FCEB; CISA encourages all organizations to prioritize KEV remediation
Note
Official product: CISA alert dated 4 September 2026 plus the KEV Catalog listing for CVE-2026-85046. Doom Signals does not invent exploit prevalence, victim counts, or autonomous-AI-attacker claims beyond CISA’s “evidence of active exploitation” framing for catalog inclusion.
BOD 26-04 applies to Federal Civilian Executive Branch agencies; CISA encourages others. This is not a private-sector mandatory deadline beyond that framing.
- Source: CISA KEV alert, 4 Sep 2026
- Catalog add: CVE-2026-85046 Chromium V8 type confusion
- GEO: omitted — catalog add, no real place pin
- Dedup: not Sep 2 LiteLLM/SonicWall seven-CVE KEV drop
Why it matters
Same-day KEV add on the Chromium V8 engine is a concrete AI/browser-attack-surface governance signal (active exploitation evidence, federal due date). Distinct from the Sep 2 LiteLLM/SonicWall seven-CVE KEV drop already boarded. Victim counts and in-the-wild exploit detail beyond CISA’s “evidence of active exploitation” framing are not invented here.
Sources
Official data. Not a forecast.