CISA KEV Catalog Addition: Adobe Commerce, Windows, and N-able N-central Actively Exploited Vulnerabilities
First seen Sep 9, 2026 · Updated Sep 9, 2026
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog affecting Adobe Commerce/Magento, Microsoft Windows, and N-able N-central, all confirmed under active exploitation. FCEB agencies must remediate per BOD 26-04, and CISA urges all organizations to prioritize patching given the demonstrated real-world attack activity.
Technical Analysis
CVE-2026-75650 is a server-side template injection flaw in Adobe Commerce/Magento allowing improper neutralization of template engine elements, potentially enabling remote code execution on e-commerce backends. CVE-2026-81963 (Windows Link Following) and CVE-2026-85880 (Windows heap-based buffer overflow) both affect the Windows OS and can be leveraged for privilege escalation or memory corruption exploitation once local access is achieved. CVE-2026-86218 is a static code injection vulnerability in N-able N-central, a remote monitoring and management (RMM) platform widely used by MSPs, making it an attractive supply-chain-style pivot point into managed environments. Organizations running AI agent orchestration, RAG pipelines, or LLM tool-use infrastructure on Windows hosts or behind RMM-managed endpoints should treat these as high priority, since exploitation of the N-central or Windows heap overflow bugs could grant attackers control of hosts running agent runtimes, exposing API keys, model credentials, and connected tool integrations.
Affected Systems
Adobe Commerce and Magento (versions affected by template engine injection), Microsoft Windows (versions vulnerable to link-following and heap-based buffer overflow), N-able N-central RMM platform (versions vulnerable to static code injection)
Indicators of Compromise
- No specific IOCs (hashes/IPs/domains) provided in source data; refer to CISA KEV Catalog and vendor advisories for CVE-2026-75650, CVE-2026-81963, CVE-2026-85880, CVE-2026-86218 for updated indicators
Remediation Steps
- 1
Apply vendor patches immediately
Update Adobe Commerce/Magento, Windows systems, and N-able N-central installations to patched versions addressing the four listed CVEs.
- 2
Prioritize per BOD 26-04
FCEB agencies must remediate these KEV entries within mandated timelines; all organizations should adopt similar risk-based prioritization.
- 3
Check for prior compromise
Per BOD 26-04 guidance, review systems for indicators of compromise predating patch deployment, especially internet-facing assets.
- 4
Audit RMM and agent-hosting infrastructure
Verify N-able N-central deployments and any Windows hosts running AI agent frameworks or LLM tool integrations for exploitation signs, and rotate any credentials/API keys potentially exposed.
- 5
Restrict exposure of vulnerable assets
Limit public exposure of Adobe Commerce/Magento instances and RMM management consoles until patched.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.