started · updated
CISA adds Microsoft, Adobe, and N-able flaws to exploited vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including flaws in Microsoft Windows, Adobe Commerce, and N-able N-central.
Adobe Commerce and Magento face a high-severity flaw (CVE-2026-75650) with a CVSS score of 10.0. Known as ‘StyleSmuggler’, this vulnerability allows unauthenticated remote code execution by placing PHP code into the platform’s templating path. It has been actively exploited since September 4 to deploy web shells and backdoors.
N-able N-central is also impacted by a static code injection vulnerability (CVE-2026-86218) with a CVSS score of 10.0. This flaw allows for pre-authentication remote code execution and has been observed being exploited in the wild. CISA has directed Federal Civilian Executive Branch agencies to apply necessary fixes by September 11, 2026.
Additionally, CISA listed a Microsoft Windows link-following vulnerability (CVE-2026-81963) that allows local attackers to gain higher privileges. Microsoft has confirmed that this flaw is also being actively exploited.