U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently expanded its Known Exploited Vulnerabilities (KEV) catalog, adding several critical vulnerabilities that require immediate attention from both federal agencies and private organizations. The newly identified vulnerabilities include significant flaws in Microsoft Windows, N-able N-central, and Adobe products, which could potentially lead to severe security breaches if left unaddressed.

Details of the Newly Added Vulnerabilities

  • CVE-2026-75650 – This vulnerability, associated with Adobe Commerce and Magento, has been assigned a CVSS score of 10.0. It involves improper neutralization of special elements used in a template engine, allowing unauthenticated remote code execution. Dubbed StyleSmuggler, this flaw has been actively exploited since September 4, enabling attackers to deploy web shells and backdoors on vulnerable online stores. Affected versions include Magento Open Source releases 2.4.7, 2.4.8, and 2.4.9.
  • CVE-2026-81963 – This Microsoft Windows vulnerability, with a CVSS score of 7.8, pertains to a link-following issue within the Update Stack. It allows local attackers to escalate their privileges by following a malicious link. Microsoft has confirmed that this flaw is currently being exploited in the wild, marking it as the first Update Stack vulnerability to be acknowledged as actively targeted by attackers.
  • CVE-2026-85880 – Another Microsoft Windows vulnerability, also rated at 7.8, involves a heap-based buffer overflow in the Advanced Local Procedure Call (ALPC) component. This flaw permits local attackers to elevate their privileges to SYSTEM level, and Microsoft has confirmed that it is being actively exploited.
  • CVE-2026-86218 – This N-able N-central vulnerability has a CVSS score of 10.0 and allows pre-authenticated remote attackers to execute arbitrary code on vulnerable systems. Given its severity, N-able has released an emergency hotfix to mitigate the risk associated with this flaw.

In accordance with Binding Operational Directive (BOD) 22-01, which aims to reduce the significant risk posed by known exploited vulnerabilities, federal agencies are required to address these identified vulnerabilities by specified deadlines. CISA has mandated that federal agencies rectify the Windows flaws by September 22, while other vulnerabilities must be addressed by September 11, 2026.

Experts strongly advise private organizations to review the KEV catalog and take necessary actions to fortify their infrastructure against these vulnerabilities. The proactive management of these risks is crucial in safeguarding networks from potential exploitation.

Winsage
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog