THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four newly observed exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue. The entries are CVE-2026-75650, CVE-2026-81963, CVE-2026-85880 and CVE-2026-86218. CVE-2026-75650 is an Adobe Commerce/Magento flaw described as an improper neutralisation of special elements used in a template engine, with a CVSS score of 10.0.
It enables unauthenticated remote code execution and has been actively exploited in the wild since 4 September, with attackers deploying web shells and backdoors. Adobe Magento Open Source releases including 2.4.7, 2.4.8 and 2.4.9 are affected.
The other three are Windows and N-able N-central issues. CVE-2026-81963 is a Windows link-following vulnerability that allows a local attacker to gain higher privileges; Microsoft confirms active exploitation in the wild. CVE-2026-85880 is a Windows heap-based buffer overflow in the ALPC component, enabling privilege escalation to SYSTEM and also reported as actively exploited.
CVE-2026-86218 concerns N-able N-central and is a pre-authenticated remote code execution flaw; N-able has released an emergency hotfix, and the vulnerability has been seen exploited in the wild. CISA’s directive under BOD 22-01 requires agencies to remediate these flaws by 22 September (Windows issues) and 11 September 2026 (the remaining items). Private organisations are advised to review the KEV catalogue and address these vulnerabilities accordingly.