Federal News
CISA Mandates Patching of Chrome Zero-Day Vulnerabilities
March 17, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) has added two critical zero-day vulnerabilities in Google Chrome to its Known Exploited Vulnerabilities list, requiring immediate patching by all federal agencies. These actively exploited flaws affect Google Chrome and other Chromium-based browsers such as Microsoft Edge, Opera, and Brave, impacting approximately 3.5 billion users worldwide. This directive underscores the urgency for government procurement and IT security teams to prioritize rapid deployment of security updates to mitigate exploitation risks.
- Why this matters: Federal agencies must comply with CISA's mandate to patch these vulnerabilities promptly to maintain cybersecurity posture and avoid potential breaches.
- Procurement professionals should ensure contracts and service agreements with software vendors include provisions for timely security patching and vulnerability management.
- Contractors providing IT and cybersecurity services can expect increased demand for rapid vulnerability assessment, patch management, and compliance verification.
- Organizations using Chromium-based browsers beyond Google Chrome should also evaluate and update their systems to align with federal cybersecurity requirements.
Agencies
Cybersecurity and Infrastructure Security Agency
Vendors
Google, Brave, Microsoft, Opera
Locations
Sources
- CISA Alerts Users to Exploited Chrome 0-Day Flaws · gbhackers.com · Mar 17
- Exploited Google Chrome zero-days added to US must-patch list - iTnews · iTnews · Mar 16