HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High ThreatIntel

State‑Aligned Threat Actors Rapidly Deploy Chrome & Windows Zero‑Day Exploit Chain (CVE‑2026‑85046, CVE‑2026‑87491, CVE‑2026‑85880)

Proofpoint reports that multiple espionage‑focused, state‑aligned groups have begun using a new exploit kit, BlueMoon, which chains two Chromium V8 zero‑days and a Windows kernel LPE. The rapid adoption underscores the urgency of continuous patch‑management and audit‑ready evidence for browser and OS vulnerabilities.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 proofpoint.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
proofpoint.com

Multiple State‑Aligned Threat Actors Rapidly Adopt Chrome & Windows Zero‑Day Exploit Chain (CVE‑2026‑85046, CVE‑2026‑87491, CVE‑2026‑85880)

What It Is – Proofpoint’s Threat Insight team observed a new exploit kit, dubbed BlueMoon, that chains three zero‑day flaws: two in Chromium’s V8 JavaScript engine (CVE‑2026‑85046, CVE‑2026‑87491) and a Windows kernel local‑privilege‑escalation bug (CVE‑2026‑85880). The kit has been adopted within days by several espionage‑motivated, state‑aligned groups, primarily China‑linked, and may spread to financially motivated actors as patches roll out.

Exploitability – All three vulnerabilities were unpatched (“patch‑gap” zero‑days) at the time of first use. Proofpoint reports active exploitation in the wild; no public proof‑of‑concept is required for an attacker to weaponize the chain once a patched binary is released.

Affected Products – Google Chrome and Chromium‑based browsers (any version that had not yet received the upstream V8 patches) and Microsoft Windows operating systems prior to the release of the kernel LPE fix.

Why It Matters for Trust & Control Assurance

  • Vulnerability‑management control – The rapid, cross‑actor adoption highlights the need for continuous, evidence‑driven patch‑tracking rather than periodic checks.
  • Audit‑ready evidence – Demonstrating that you have up‑to‑date remediation evidence for browser and OS patches satisfies multiple framework objectives (e.g., NIST CSF “Detect” and ISO 27001 “Asset Management”).
  • Supply‑chain vigilance – The exploit kit’s reuse across unrelated groups shows that a single unpatched component can become a shared attack surface, demanding a unified view of third‑party and internal asset exposure.

Recommended Actions

  • Verify that all Chrome/Chromium browsers and Windows endpoints are running the latest patches that address CVE‑2026‑85046, CVE‑2026‑87491, and CVE‑2026‑85880.
  • Enable continuous vulnerability‑management tooling that automatically collects patch‑status evidence and maps it to your control framework.
  • Review your incident‑response playbooks for zero‑day exploitation scenarios, ensuring forensic logging is enabled on browsers and OS kernels.

Source: Proofpoint Threat Insight – BlueMoon Exploit Kit

📰 Original Source
https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →