Threat Brief — 2026-09-05 — KEV catalog churn continues
Executive summary. Today's sole fresh feed item is a re-entry of CVE-2026-85046KEV (Google Chromium V8 type confusion) appearing in CISA's Known Exploited Vulnerabilities catalog. This is not a new development: the same CVE-2026-85046KEV KEV addition was first reported yesterday, 2026-09-04, by The Hacker News. No additional technical detail, patch revision, or exploit evolution has surfaced in the intervening period. The vulnerability remains actively exploited in the wild per CISA's catalog.
Top items
- CVE-2026-85046KEV — Google Chromium V8 type confusion (CISA KEV, no new development). A type confusion in the V8 JavaScript engine allows remote code execution within the Chromium sandbox via a crafted HTML page. CISA has listed this CVE in its Known Exploited Vulnerabilities catalog, confirming active exploitation. This is a continuation of a story first reported 2026-09-04 by The Hacker News; today's finding adds no new technical or operational detail beyond the KEV listing already covered. (src: CISA KEV) (first reported: The Hacker News)
Themes
Browser zero-days remain the highest-frequency KEV additions. CVE-2026-85046KEV joins a pattern of Chromium V8 flaws reaching in-the-wild exploitation before broad patch adoption. Organisations should prioritise Chromium-based browser update cadence as a frontline control, since these vulnerabilities typically require only user interaction with a malicious page.
