What you need to know today.
N-able N-central RCE and Adobe Commerce zero-day added to KEV; Microsoft releases record 974 CVEs.

A critical remote code execution vulnerability in N-able N-central, CVE-2026-86218, has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. This pre-authentication flaw allows unauthenticated attackers to execute arbitrary code on affected systems. N-able has released multiple hotfixes to address this issue, with the latest being version 2026.3.1.14. The vulnerability has been actively exploited in the wild, prompting urgent attention from security teams. As reported by The Hacker News and Infosecurity Magazine, this marks the fourth hotfix N-able has issued in five weeks, highlighting the severity and persistence of the exploitation attempts.
Adobe Commerce is grappling with CVE-2026-75650, a critical vulnerability that has also been added to the CISA KEV catalog. This flaw, stemming from improper neutralization of special elements in a template engine, allows for arbitrary code execution within the context of the current user. SecurityWeek and The Hacker News report that this zero-day has been exploited in the wild to deploy backdoors and web shells. Adobe has released patches as part of a larger security update addressing over 170 vulnerabilities, including other critical flaws in Adobe Campaign Classic (CVE-2026-82004) and ColdFusion (CVE-2026-48273).
Lantronix's EDS5000 devices are affected by CVE-2025-67038, a critical vulnerability that has seen exploitation in the wild and is now listed on CISA's KEV catalog. The flaw resides in the HTTP RPC module, where a failure to sanitize usernames directly concatenated into shell commands for log writing enables remote, unauthenticated attackers to achieve arbitrary code execution. BleepingComputer and The Hacker News have highlighted CISA's warnings regarding this vulnerability, noting its presence in OT environments. This vulnerability was previously flagged by CISA in June.
Microsoft's September Patch Tuesday addresses a staggering 974 CVEs, including several critical vulnerabilities. Among these is CVE-2026-66302, a remote code execution flaw in Skype for Business, and CVE-2026-78510, a heap-based buffer overflow in Microsoft Office Word, both allowing unauthorized network-based code execution. Additionally, CVE-2026-83941, a critical missing authorization vulnerability in Entra ID, could allow an attacker to elevate privileges over a network. The Register and Dark Reading have noted this as a record-breaking Patch Tuesday for Microsoft, underscoring the broad impact of this update.
SAP has released patches for a critical vulnerability, CVE-2026-44756, affecting its Extended Passport Protocol (EPP) processing library. This vulnerability, rated with a CVSS score of 10.0, allows an unauthenticated attacker to execute arbitrary code by sending a crafted network request with a malformed EPP header. Infosecurity Magazine and The Hacker News report that SAP has patched this "Overpass" flaw, emphasizing its critical nature and potential for unauthenticated remote code execution. This is part of SAP's September security updates, which also address vulnerabilities in NetWeaver and cloud products.
Android security updates for September 2026 include fixes for critical vulnerabilities, such as CVE-2026-49921 and CVE-2026-58822, both related to memory safety issues (heap buffer overflow and improper casting, respectively) that could lead to remote code execution without user interaction. Cyber Security News highlights these critical flaws, noting that they do not require additional execution privileges for exploitation. These updates are part of a broader Android security bulletin addressing numerous vulnerabilities across the platform.