VORANT. Threat Intelligence Sign in Get the full feed

CISA KEV adds Adobe, Windows, N-central bugs

severe vulnerability government-nationalretailtechnology

CISA added four actively exploited vulnerabilities in Adobe Commerce/Magento, Windows, and N-able N-central to its Known Exploited Vulnerabilities catalog.

CISA has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: a template injection flaw in Adobe Commerce and Magento, a link-following vulnerability and a heap-based buffer overflow in Microsoft Windows, and a static code injection vulnerability in N-able N-central. No technical exploitation details, threat actor attribution, or malware associated with the campaigns were disclosed in this bulletin.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets that could grant an attacker total control post-exploitation, and to check for prior compromise before patching. While BOD 26-04 formally applies only to FCEB agencies, CISA recommends all organizations adopt the same risk-based prioritization for these four CVEs given confirmed in-the-wild exploitation.

Defenders should inventory affected Adobe Commerce/Magento instances, Windows systems, and N-able N-central deployments, apply vendor patches promptly, and review logs for indicators of compromise predating patch application, consistent with BOD 26-04 guidance.

Mentioned in this report

Vulnerabilities CVE-2026-75650KEVCVE-2026-81963KEVCVE-2026-85880KEVCVE-2026-86218KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free