VYPR
Published Sep 8, 2026· Updated Sep 10, 2026· 1 source

CVE-2026-75650 Added to CISA KEV Under Active Exploitation

Key findings • CVE-2026-75650, an Adobe vulnerability, is now on CISA's KEV catalog. • The flaw is confirmed to be actively exploited in real-world attacks. • All organizations should pri…

Key findings

  • CVE-2026-75650, an Adobe vulnerability, is now on CISA's KEV catalog.
  • The flaw is confirmed to be actively exploited in real-world attacks.
  • All organizations should prioritize patching this vulnerability immediately.
  • Federal agencies must remediate CVE-2026-75650 by September 8, 2026.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert by adding a significant Adobe vulnerability, identified as CVE-2026-75650, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition confirms that the flaw is under active exploitation by threat actors in real-world attacks, elevating its risk profile for organizations globally. The inclusion in the KEV catalog serves as a critical warning, mandating immediate attention and remediation from federal civilian executive branch agencies and strongly advising all other organizations to follow suit.

CVE-2026-75650 represents a singular, actively exploited vulnerability within Adobe's product ecosystem. While specific details regarding the affected product or the nature of the flaw are not publicly detailed in the KEV entry beyond its identifier, its presence on the catalog signifies a severe threat. Actively exploited vulnerabilities are prime targets for attackers seeking unauthorized access, data exfiltration, or system disruption, making swift mitigation essential to prevent potential breaches.

There is no indication from the CISA KEV catalog entry that CVE-2026-75650 is currently associated with ransomware campaigns. However, any actively exploited vulnerability carries the potential for severe consequences, including being leveraged as an initial access vector for broader attacks that could eventually lead to ransomware deployment or other malicious activities.

For all organizations utilizing Adobe products, the immediate priority must be to identify and apply the necessary patches or mitigations for CVE-2026-75650. CISA's directive requires federal agencies to remediate this vulnerability by September 8, 2026. This deadline should serve as a benchmark for all entities, emphasizing the urgency of addressing this critical flaw. Organizations should consult official Adobe security advisories for specific patching instructions and prioritize these updates within their vulnerability management programs to safeguard their systems against ongoing threats.

Synthesized by Vypr AI