Machine-generated analysis · WAYSCloud LLM
Four CVEs affecting Adobe Commerce/Magento, Microsoft Windows, and N-able N-central have been added to CISA’s KEV Catalog.
Context
The advisory lists CVE-2026-75650 (Adobe Commerce and Magento template engine), CVE-2026-81963 (Microsoft Windows link following), CVE-2026-85880 (Microsoft Windows heap-based buffer overflow), and CVE-2026-86218 (N-able N-central static code injection). CISA states these vulnerabilities are actively exploited and should be prioritized for remediation on publicly exposed assets. BOD 26-04 directs federal agencies to remediate such high-risk flaws rapidly.
Operator considerations
Check: Inventory systems running Adobe Commerce/Magento, Microsoft Windows, and N-able N-central.
Isolate: Segment or restrict public access to any exposed instances of these products.
Patch: Apply any vendor-released patches or mitigations for the listed CVEs as soon as possible.
Log: Monitor logs for exploitation attempts related to template engine processing, link handling, heap overflows, or code injection.
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
CVE-2026-81963 Microsoft Windows Link Following Vulnerability
CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability
CVE-2026-86218 N-able N-central Static Code Injection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies t...
Read the full advisory on CISA →