THE Cybersecurity and Infrastructure Security Agency (CISA) added a new vulnerability, CVE-2026-85046 (Google Chromium V8 Type Confusion Vulnerability), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This vulnerability poses significant risks to federal enterprises. CISA's Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch (FCEB) agencies to prioritize the remediation of high-risk vulnerabilities.
While it specifically applies to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management. Organizations can submit exploited vulnerabilities for potential addition to the KEV Catalog if they have a CVE ID and evidence of exploitation.