This day 02:06 06:06 10:07 14:07 18:07 22:08
⚠ exploit status: CVE-2026-85046 · KEV
High  2026-09-05 02:06Z · last 4h · 1 findings · glm-5.2:cloud

Threat Brief — 2026-09-05 — KEV catalog churn continues

Executive summary. Today's sole fresh feed item is a re-entry of CVE-2026-85046KEV (Google Chromium V8 type confusion) appearing in CISA's Known Exploited Vulnerabilities catalog. This is not a new development: the same CVE-2026-85046KEV KEV addition was first reported yesterday, 2026-09-04, by The Hacker News. No additional technical detail, patch revision, or exploit evolution has surfaced in the intervening period. The vulnerability remains actively exploited in the wild per CISA's catalog.


Top items


Themes

Browser zero-days remain the highest-frequency KEV additions. CVE-2026-85046KEV joins a pattern of Chromium V8 flaws reaching in-the-wild exploitation before broad patch adoption. Organisations should prioritise Chromium-based browser update cadence as a frontline control, since these vulnerabilities typically require only user interaction with a malicious page.


Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db