The US Cybersecurity and Infrastructure Security Agency (CISA) added several new vulnerabilities to its Known Exploited Vulnerabilities catalog this month, meaning attackers are actively using these flaws right now, not just theorising about them.
- What it is: CISA confirmed multiple software vulnerabilities, including a Google Chromium flaw (CVE-2026-85046), are being exploited in real attacks, with further batches added across September.
- Who is affected: Any business running Chrome or Chromium-based browsers, or other affected software on the list, on Windows, Mac or Linux devices.
- What the risk is: Attackers can exploit these flaws in some cases with no user interaction, potentially gaining control of affected systems.
- What action is needed: Make sure browser and operating system updates are set to install automatically, and confirm patch status across your fleet rather than relying on individual staff to update manually.
We recommend a quick patch status check this week if you have not reviewed it recently. Source: CISA Cybersecurity Advisories.