Google: Critical Flaw Added to CISA KEV Under Active Exploitation
Key findings • Google vulnerability CVE-2026-87491 added to CISA KEV catalog. • The flaw is confirmed to be under active exploitation in the wild. • No ransomware association has been rep…

Key findings
- Google vulnerability CVE-2026-87491 added to CISA KEV catalog.
- The flaw is confirmed to be under active exploitation in the wild.
- No ransomware association has been reported for this vulnerability.
- Immediate patching and security updates are crucial for affected Google products.
- Federal agencies are required to remediate CVE-2026-87491 by October 9, 2026.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert by adding a significant Google vulnerability, identified as CVE-2026-87491, to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion signals that the flaw is under active exploitation by malicious actors, elevating its status to an urgent security concern for organizations and users globally.
CVE-2026-87491 represents a critical security gap within Google's ecosystem. While specific product details were not immediately disclosed with its KEV listing, the confirmation of active exploitation underscores the immediate threat it poses. Attackers are leveraging this vulnerability to compromise systems, making prompt remediation essential to prevent potential breaches and data loss.
There is no indication from the current CISA listing that CVE-2026-87491 is associated with ransomware campaigns. However, active exploitation of any vulnerability can lead to various forms of compromise, including unauthorized access, data exfiltration, or the deployment of other malicious payloads, regardless of ransomware involvement.
Organizations and individual users of Google products are strongly advised to prioritize the immediate application of any available patches or security updates related to CVE-2026-87491. CISA's directive mandates that federal civilian executive branch agencies remediate this vulnerability by October 9, 2026, highlighting the critical need for swift action across all sectors to mitigate the risk posed by this actively exploited flaw.