CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-85046, a Google Chromium V8 type confusion vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability is actively being exploited and presents a significant risk to federal agencies. Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize fixing vulnerabilities listed in the KEV Catalog. This directive specifically targets high-risk vulnerabilities on publicly exposed assets that lead to complete control upon exploitation. BOD 26-04 also outlines requirements for federal agencies to check for compromise before patching. While the BOD applies only to FCEB agencies, CISA recommends that all organizations adopt this risk-based approach. The agency will continue to add vulnerabilities to the KEV Catalog as they meet the criteria. Organizations can nominate vulnerabilities for inclusion if they have a CVE ID, proof of exploitation, and clear mitigation steps. This active management of exploited vulnerabilities is crucial for cybersecurity.