VYPR
kevPublished Sep 8, 2026· 1 source

CISA Adds Four Exploited Vulnerabilities to KEV Catalog, Including Microsoft, Adobe, and N-able Flaws

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation and urging prioritized patching.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of four new vulnerabilities to its publicly accessible Known Exploited Vulnerabilities (KEV) Catalog. This action is based on confirmed evidence that these vulnerabilities are actively being exploited by malicious cyber actors, posing significant risks to organizations.

The newly cataloged vulnerabilities include CVE-2026-75650, an Improper Neutralization of Special Elements Used in a Template Engine vulnerability affecting Adobe Commerce and Magento. Additionally, two vulnerabilities in Microsoft Windows have been added: CVE-2026-81963, a Link Following Vulnerability, and CVE-2026-85880, a Heap-Based Buffer Overflow Vulnerability. Finally, CVE-2026-86218, a Static Code Injection Vulnerability in N-able's N-central platform, has also been included.

These types of vulnerabilities are frequently leveraged by threat actors as attack vectors. Their inclusion in the KEV Catalog signifies a heightened risk, particularly for federal agencies. CISA's Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize the remediation of vulnerabilities listed in the KEV Catalog, especially those on publicly exposed assets that could lead to full system control post-exploitation.

BOD 26-04 emphasizes a risk-based approach to vulnerability management, requiring agencies to address high-risk vulnerabilities promptly. The directive also establishes expectations for agencies to check for signs of compromise on systems before applying patches, a critical step in mitigating the impact of exploited vulnerabilities. While the directive specifically targets FCEB agencies, CISA strongly encourages all organizations to adopt similar risk-based vulnerability management practices.

The inclusion of these four vulnerabilities underscores the dynamic nature of the threat landscape and the continuous efforts by CISA to identify and publicize actively exploited weaknesses. Organizations are advised to consult the KEV Catalog regularly and implement timely patching and mitigation strategies to protect their networks.

CISA maintains the KEV Catalog to provide a clear list of vulnerabilities that pose an immediate and significant threat. The agency relies on evidence of active exploitation to determine additions, ensuring that the catalog reflects the most pressing risks to cybersecurity.

Organizations that become aware of an exploited vulnerability not yet listed in the KEV Catalog are encouraged to submit it for consideration through CISA's KEV Nomination Form. To be considered for addition, a vulnerability must have a designated CVE ID, demonstrable evidence of exploitation, and clear guidance on mitigation or remediation.

CISA will continue to monitor the threat landscape and update the KEV Catalog as new actively exploited vulnerabilities are identified, reinforcing its commitment to enhancing the nation's cybersecurity posture.

Synthesized by Vypr AI