# BlueMoon Exploit Kit Rapidly Weaponizes Recent Zero-Day Vulnerabilities

*Published September 14, 2026*
*Source: [https://www.securityweek.com/bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days/](https://www.securityweek.com/bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/bluemoon-exploit-kit-rapidly-weaponizes-recent-zero-day-vulnerabilities) or [see plans](https://www.sec-news.ai/pricing).*

## Article

A new exploit kit named BlueMoon has been identified as a tool used by multiple espionage groups, according to cybersecurity firm Proofpoint. Initially deployed by the China-linked APT group Violet Typhoon on August 28, the exploit kit quickly spread to other threat actors, including UNK_LateNight and UNK_QuietRacket, targeting various sectors such as aerospace and government entities in the US and Southeast Asia. BlueMoon is particularly dangerous because it chains together three unpatched vulnerabilities: two zero-days in the Chrome browser and one in Windows. The Chrome vulnerabilities, identified as CVE-2026-85046 and CVE-2026-87491, were found in the V8 JavaScript and WebAssembly engine and have since been patched. The Windows zero-day, CVE-2026-85880, involved a privilege escalation issue in Windows Advanced Local Procedure Call and was addressed in September's Patch Tuesday.

Proofpoint's analysis revealed that BlueMoon exploits these flaws to escape the V8 sandbox, fingerprint the host, execute privilege escalation, and ultimately download and run malicious executables. The exploit kit's rapid adoption and variation among threat actors suggest a reduced barrier to entry, potentially aided by AI in its development. Despite the fast deployment, detection signals were high, indicating the presence of significant threats to the affected sectors.

The initial targets of BlueMoon were non-governmental organizations in the US, as well as firms involved in mining and physical commodity trading. By early September, it had spread to aerospace companies and a manufacturing organization in Vietnam, further demonstrating its widespread impact. Proofpoint's findings highlight the growing ease with which such exploit kits can be developed and deployed, underscoring the urgent need for vigilant security measures.
