CISA Adds Multiple Critical Vulnerabilities to Exploited Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Microsoft Windows, N-able N-central, and Adobe.
CVE-2026-75650 is a critical vulnerability in Adobe Commerce and Magento that can lead to unauthenticated remote code execution. According to Sansec researchers, the flaw has been actively exploited since September 4, with attackers deploying web shells and backdoors on vulnerable online stores.
Microsoft Windows Update Stack link-following vulnerability (CVE-2026-81963) allows a local attacker to gain higher privileges, while CVE-2026-85880 is a Microsoft Windows heap-based buffer overflow in the Advanced Local Procedure Call (ALPC) component that also allows an attacker to elevate privileges.
CISA orders federal agencies to fix the Windows flaws by September 22, while the remaining vulnerabilities must be addressed by September 11, 2026. Experts recommend that private organizations review the catalog and address the vulnerabilities in their infrastructure to protect against attacks exploiting these flaws.