Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

U.S. CISA Adds Microsoft Windows, N-able N-central, and Adobe Flaws to Its Known Exploited Vulnerabilities Catalog: A Security Alert




The U.S. CISA has added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including Microsoft Windows, N-able N-central, and Adobe flaws. These vulnerabilities have been identified as actively exploited in the wild and pose a significant threat to organizations. It is essential for organizations to stay informed and take proactive measures to address these vulnerabilities and protect their systems and networks.



  • CISA has added several vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including Microsoft Windows, N-able N-central, and Adobe flaws.
  • CVE-2026-75650, an Adobe Commerce and Magento improper neutralization of special elements in a template engine vulnerability, has been actively exploited since September 4.
  • CVE-2026-81963, a Microsoft Windows Update Stack link-following vulnerability, allows a local attacker to gain higher privileges and is being actively exploited in the wild.
  • CVE-2026-85880, a Microsoft Windows heap-based buffer overflow in the Advanced Local Procedure Call (ALPC) component, allows a local attacker to elevate privileges to SYSTEM.
  • CVE-2026-86218, an N-able N-central static code injection vulnerability, allows a pre-authenticated remote attacker to execute arbitrary code on vulnerable systems.
  • Organizations must prioritize the security of their systems and networks and take immediate action to patch and address any identified vulnerabilities.



  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added several vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, a critical resource for organizations to stay informed about and address potential security threats. The additions include Microsoft Windows, N-able N-central, and Adobe flaws, which have been identified as actively exploited in the wild.

    Among the newly added vulnerabilities is CVE-2026-75650, an Adobe Commerce and Magento improper neutralization of special elements in a template engine vulnerability. This flaw, tracked as StyleSmuggler, has been actively exploited since September 4, with attackers using it to deploy web shells and backdoors. The vulnerability affects current Magento Open Source releases, including 2.4.7, 2.4.8, and 2.4.9. According to Sansec researchers, exploitation began on September 4, with StyleSmuggler working by placing PHP code into Magento’s templating path and later causing the platform to evaluate it. The first stage creates or poisons a record, while the second stage turns a routine email-rendering process into remote code execution.

    Another critical vulnerability added to the KEV catalog is CVE-2026-81963, a Microsoft Windows Update Stack link-following vulnerability that allows a local attacker to gain higher privileges. Microsoft has confirmed that the flaw is being actively exploited in the wild, and it is the first Update Stack vulnerability that Microsoft has confirmed attackers are actively exploiting.

    Additionally, CVE-2026-85880, a Microsoft Windows heap-based buffer overflow in the Advanced Local Procedure Call (ALPC) component, has been added to the catalog. This vulnerability allows a local attacker to elevate privileges to SYSTEM. Microsoft has confirmed active exploitation of the vulnerability.

    Lastly, CVE-2026-86218, an N-able N-central static code injection vulnerability, has been added to the catalog. This vulnerability allows a pre-authenticated remote attacker to execute arbitrary code on vulnerable systems. The flaw has been exploited in the wild, and N-able released an emergency hotfix to address it.

    CISA has ordered federal agencies to fix the Windows flaws by September 22, while the remaining must be addressed by September 11, 2026. Experts also recommend that private organizations review the catalog and address the vulnerabilities in their infrastructure.

    The addition of these vulnerabilities to the KEV catalog serves as a reminder of the importance of staying informed about potential security threats and taking proactive measures to address them. Organizations must prioritize the security of their systems and networks, and take immediate action to patch and address any identified vulnerabilities.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Microsoft-Windows-N-able-N-central-and-Adobe-Flaws-to-Its-Known-Exploited-Vulnerabilities-Catalog-A-Security-Alert-ehn.shtml

  • https://securityaffairs.com/198802/hacking/u-s-cisa-adds-microsoft-windows-n-able-n-central-and-adobe-flaws-to-its-known-exploited-vulnerabilities-catalog.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-75650

  • https://www.cvedetails.com/cve/CVE-2026-75650/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-81963

  • https://www.cvedetails.com/cve/CVE-2026-81963/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85880

  • https://www.cvedetails.com/cve/CVE-2026-85880/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-86218

  • https://www.cvedetails.com/cve/CVE-2026-86218/


  • Published: Thu Sep 10 03:39:36 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us