rootpwn

Advisories

CISA Expands KEV Catalog with Four Fresh Exploited Vulnerabilities

The Cybersecurity and Infrastructure Security Agency has added four new CVEs to its Known Exploited Vulnerabilities catalog, covering a critical Adobe Commerce flaw, two Microsoft Windows weaknesses, and a N‑able N‑central code injection. The update reinforces BOD 26‑04’s risk‑based patching mandate for federal agencies and urges all organizations to prioritize these high‑risk fixes and submit any other exploited CVEs for consideration.

In a move that tightens the net around the most dangerous software bugs, CISA has just bolstered its Known Exploited Vulnerabilities (KEV) catalog with four new CVEs that have been proven in the wild.

New Vulnerabilities Added

  • CVE‑2026‑75650 – Improper neutralization of special elements in Adobe Commerce/Magento’s template engine, allowing attackers to inject malicious content.
  • CVE‑2026‑81963 – A link‑following flaw in Microsoft Windows that can be abused to redirect users to malicious sites.
  • CVE‑2026‑85880 – A heap‑based buffer overflow in Microsoft Windows that can lead to arbitrary code execution.
  • CVE‑2026‑86218 – Static code injection in N‑able N‑central, giving attackers the ability to run arbitrary commands on the server.

Implications for Federal Agencies

Under Binding Operational Directive 26‑04, federal civilian executive branch agencies must treat these KEV entries as high‑risk. The directive requires rapid remediation of any publicly exposed asset that could grant full control to an attacker, while lower‑risk issues may be deferred. Agencies are also expected to verify whether a system has been compromised before applying a patch.

"Prioritizing Security Updates Based on Risk" – the core of BOD 26‑04, demanding that KEV vulnerabilities be patched first on exposed assets.

What to Do Now

All organizations, not just federal ones, should immediately check if any of these CVEs affect their environment and apply the available mitigations. If you suspect an exploitation has occurred, isolate the affected system and document the incident. Additionally, if you know of another exploited CVE that isn’t yet in the catalog, submit it through CISA’s KEV Nomination Form. A valid nomination must include a CVE ID, proof of exploitation, and clear mitigation guidance.

CISA KEV Adobe Microsoft N‑able Vulnerability Management

← All news