CISA KEV Alert 10 Sept 2026, 01:32 UTC

CISA Warns of Actively Exploited Chromium Flaw Enabling Code Execution

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA has added CVE-2026-87491 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Google Chromium V8 and is an out-of-bounds write flaw that can allow remote code execution inside the browser sandbox through a crafted HTML page. It may also affect Chromium-based browsers, including Google Chrome, Microsoft Edge and Opera.

The flaw allows an attacker to write beyond an allocated memory boundary. A remote attacker can exploit it by directing a victim to a crafted HTML page, potentially executing arbitrary code within the sandbox. The vulnerability has a CVSS score of 8.8 and is rated High. A patch is available through Google’s stable channel update for desktop.

CISA’s KEV listing confirms that attackers are actively exploiting this vulnerability. The available data does not identify known ransomware campaign use. Federal Civilian Executive Branch (FCEB) agencies must remediate the flaw by 23 September 2026.

CISA requires organisations to apply mitigations in accordance with vendor instructions and follow applicable BOD 26-04 guidance on prioritising security updates based on risk, including requirements for cloud services where relevant. Organisations should discontinue use if mitigations are unavailable. FCEB agencies are directly affected by this requirement, while all organisations should review their exposure across Chromium-based browsers, assess internet-facing assets and apply the available update.

See the NVD entry and CISA KEV catalogue for full details: https://nvd.nist.gov/vuln/detail/CVE-2026-87491 and https://www.cisa.gov/known-exploited-vulnerabilities-catalog.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline