BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Proofpoint has reported active in-the-wild exploitation by a new exploit kit named BlueMoon, which chains three previously unpatched vulnerabilities to target espionage-driven campaigns. The attack sequence combines two Google Chrome V8 engine zero-days, identified as CVE-2026-85046 and CVE-2026-87491, with a Microsoft Windows privilege escalation flaw in the Advanced Local Procedure Call component tracked as CVE-2026-85880.
Multiple China-linked threat actors, including Violet Typhoon, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, have rapidly adopted this toolkit for attacks on NGOs, aerospace firms, and government entities. While the Chrome vulnerabilities were addressed on September 3 and September 8, the Windows defect was resolved during the September 2026 Patch Tuesday cycle, underscoring the urgent need for immediate patching across affected systems.