CISA KEV adds Adobe, Windows, N-central bugs
CISA added four actively exploited vulnerabilities in Adobe Commerce/Magento, Windows, and N-able N-central to its Known Exploited Vulnerabilities catalog.
CISA has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation: a template injection flaw in Adobe Commerce and Magento, a link-following vulnerability and a heap-based buffer overflow in Microsoft Windows, and a static code injection vulnerability in N-able N-central. No technical exploitation details, threat actor attribution, or malware associated with the campaigns were disclosed in this bulletin.
Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets that could grant an attacker total control post-exploitation, and to check for prior compromise before patching. While BOD 26-04 formally applies only to FCEB agencies, CISA recommends all organizations adopt the same risk-based prioritization for these four CVEs given confirmed in-the-wild exploitation.
Defenders should inventory affected Adobe Commerce/Magento instances, Windows systems, and N-able N-central deployments, apply vendor patches promptly, and review logs for indicators of compromise predating patch application, consistent with BOD 26-04 guidance.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free