Check the KEV feed first. Before you open a random severity spreadsheet, open CISA’s Known Exploited Vulnerabilities catalog at cisa.gov/known-exploited-vulnerabilities-catalog and the CSV or JSON feeds that sit beside it. Under Binding Operational Directive 26-04 thinking, those feeds are prioritisation input: verify your asset inventory against newly added CVEs, patch internet-facing systems first, and treat legacy estates as equally in scope when they still answer on a network path.

Today’s worked example is one recent add — Chromium CVE-2026-85046 — walked as a defender’s checklist with no exploit steps. This howto is distinct from the earlier “read the KEV before you patch” drill that used the 2 September seven-CVE set. Same catalogue. Different habit: feed-first, inventory-second, internet-facing-third, legacy-not-forgotten.

What the feed is for. KEV is CISA’s public list of vulnerabilities with evidence of exploitation in the wild. The catalog page is human-readable. The CSV and JSON feeds are machine-readable. BOD 26-04 is the federal civilian directive that turns KEV rows into remediation clocks for Federal Civilian Executive Branch agencies. You do not need to be an FCEB shop to steal the method. You need a browser, a spreadsheet or CMDB export, and the discipline to diff today’s feed against yesterday’s.

Tap to enlarge

Step one — load the catalog and the feed, not a Twitter screenshot. Go to cisa.gov/known-exploited-vulnerabilities-catalog. Confirm you are on the live agency page. Download or poll the JSON or CSV feed your operations team already trusts. If you automate, store a daily snapshot. If you do not automate yet, save today’s CSV with a date stamp in the filename. The habit is the point. A feed you never diff is just a PDF with worse typography.

Step two — find the new rows. Sort by date added or diff against yesterday’s snapshot. On 4 September 2026, CVE-2026-85046 appears as a Google Chromium V8 type confusion add with active exploitation cited. Read the vendor, product, vulnerability name, and date added exactly as printed. Note any due-date field the live row carries for federal readers. If a secondary summary said an announcement lacked a deadline or a products/versions list, believe the live catalog over the newspaper when they disagree. Don’t invent a date the row does not show.

Step three — inventory before adrenaline. Export browsers and Chromium-based runtimes from your endpoint tool, MDM, or software inventory. Include kiosks, VDI golden images, build agents that launch headless Chrome, and anything that embeds a Chromium webview if your SBOM or package inventory can see it. Match product names, not vibes. “We only use Edge” is still a Chromium-engine question on many estates. “We only use Safari” may still leave a managed Chrome ring for staff who installed it. Write the discovery method into the ticket.

Step four — internet-facing first, then the long tail. BOD 26-04 thinking prioritises publicly exposed assets that grant serious control after exploitation. For a browser CVE, the analogue is high-touch browsing estates and any internet-facing service that embeds Chromium in a way your edge inventory can see. Patch those rings first. Then the standard managed laptops. Then the forgotten lab PC that still browses the open web on an old channel. Legacy is in scope if it can still fetch a page. Equal dignity for old metal is not nostalgia — it is how real breaches skip the shiny MDM fleet.

Worked example, CVE-2026-85046, defender-only. Catalog date to write down: 4 September 2026. CVE string: CVE-2026-85046. Product class: Google Chromium V8. Class name on the book: type confusion. Directive context for federal shops: BOD 26-04. Action you take: identify Chromium and Chromium-derived browsers in inventory; apply vendor security updates through your normal browser update channels; verify version strings on a sample; record the CVE in the closed change. Action you do not take: search for a proof of concept, open a crafted HTML file, or follow a blog that wants to “reproduce safely.” Reproduction is not required to patch.

How this howto differs from “read the KEV before you patch.” That earlier drill taught page literacy on the 2 September seven-add set — Sangoma, Starlette, Kestra, LiteLLM, Artifactory, two SonicWall SMA1000 entries — and the BOD clock language around them. This drill teaches feed operations: snapshot, diff, inventory match, internet-facing priority, legacy inclusion, and a single Chromium worked example. Keep both habits. Do not merge the articles into one slurried checklist.

CSV versus JSON, practical notes. CSV is what tired humans open in a sheet to filter date-added and vendor columns. JSON is what a small script diffs against an SBOM or a vulnerability management API. Either feed is fine if you actually use it. For a small team: one daily diff job, one Slack or ticket ping when the diff is non-empty, one owner who maps new CVEs to asset groups before standup ends. That is enough machinery to beat a weekly PDF ritual.

Asset inventory honesty check. If your CMDB cannot answer “where is Chromium,” your KEV process is theatre. Spend the hour on inventory quality before you spend the hour on severity debate. Package lockfiles, endpoint installed-software tables, MDM compliance boards, and container base-image scans are four ordinary places Chromium hides. Write which one you used. Next week’s person should not rediscover the same shadow IT browser ring from scratch.

Internet-facing first, explained without drama. A VPN concentrator on KEV and a browser on KEV are different shapes, but the directive habit still helps: anything that touches untrusted networks jumps the queue. For browsers, that means users who handle open internet content as their job — research, journalism, customer support, SOC analysts — get the forced update ring before the offline accounting laptop that opens spreadsheets. Then you still patch the accounting laptop. Order is prioritisation, not exemption.

Legacy equally in scope. Windows 10 holdouts, old Macs on deferred update rings, thin clients, conference-room panels that launch a browser, and digital-signage boxes are where “we patched Chrome” statements go to die. If the device can retrieve web content, CVE-2026-85046 thinking applies until the device is gone or the browser is updated. Decommission is a valid remediation. Ignoring is not.

What this howto will never include. Exploit steps. Proof-of-concept code. Payload shapes. “Lab validation” recipes against public sites. Instructions for triggering a V8 type confusion. The vulnerability class name is enough to prioritise. Vendor fixed builds are enough to remediate. If your auditor asks how you validated, show the version string and the KEV row, not a crash demo.

Weekly rhythm you can keep. Monday: diff the KEV JSON against last Monday. Same day: open tickets for matches. Tuesday: internet-facing and high-touch rings. Wednesday: standard managed estates. Thursday: legacy and exceptions board. Friday: verify samples and close with CVE IDs in titles. When CISA adds something mid-week — as with CVE-2026-85046 on 4 September 2026 — run an out-of-band diff the same day. The feed is the pager, not the Friday meeting.

Federal versus everyone else. If you are FCEB, BOD 26-04 due dates on the live KEV row are your clocks — read them from the agency, not from a secondary summary that may have noted missing fields on day one. If you are not FCEB, still use the feed as prioritisation input and still prefer exploited-in-the-wild over theoretical criticals that never leave a lab. The directive’s thinking is useful even when the directive’s legal force is not.

Restate the numbers. Catalog URL: cisa.gov/known-exploited-vulnerabilities-catalog. Feeds: CSV and JSON from the same CISA KEV program. Directive mindset: BOD 26-04. Worked CVE: CVE-2026-85046, added 4 September 2026, Chromium V8 type confusion. Priority order: inventory match, internet-facing and high-touch first, legacy still in scope. Distinct from the 2 September seven-CVE reading drill. No exploit content. Patch via vendor browser updates. Diff the feed. Then touch the metal.

Last spoken line. Check the KEV feed first. Snapshot it. Diff it. Match it to assets you can actually name. Patch the exposed and the forgotten. Use CVE-2026-85046 as the practice row this week without asking anyone how to break V8. Catalog, feed, inventory, fix, verify. That is the howto.