rootpwn

Advisories

CISA Expands KEV Catalog with Four New Exploited Vulnerabilities

CISA has added four new CVEs to its Known Exploited Vulnerabilities catalog, covering critical flaws in Adobe Commerce, Microsoft Windows, and N‑central. The update highlights the agency’s push for rapid remediation of high‑risk flaws and reinforces BOD 26‑04’s prioritization rules for federal agencies.

In a move to tighten the federal security posture, the Cybersecurity and Infrastructure Security Agency (CISA) has broadened its Known Exploited Vulnerabilities (KEV) catalog. The agency’s latest update lists four CVEs that have been confirmed as actively exploited in the wild.

New KEV Entries

  • CVE‑2026‑75650 – Improper neutralization of special elements in Adobe Commerce and Magento’s template engine.
  • CVE‑2026‑81963 – Windows link‑following flaw that can be abused to execute arbitrary code.
  • CVE‑2026‑85880 – Heap‑based buffer overflow in Microsoft Windows, allowing attackers to gain full control.
  • CVE‑2026‑86218 – Static code injection vulnerability in N‑able N‑central, exposing sensitive data and permitting remote code execution.

These vulnerabilities represent common attack vectors for malicious actors and carry significant risk to federal systems that are publicly exposed. They are now part of CISA’s KEV catalog, which is a key resource for prioritizing patching efforts.

Implications for Federal Agencies

Under Binding Operational Directive (BOD) 26‑04, federal civilian executive branch agencies must prioritize rapid remediation of KEV-listed flaws that grant total control over an asset. The directive also requires agencies to verify whether a system has been compromised before a patch is applied. While BOD 26‑04 applies only to federal agencies, CISA urges all organizations to adopt a risk‑based approach and focus on KEV vulnerabilities first.

How to Get Your Vulnerability Added

If you discover an actively exploited flaw that isn’t yet in the KEV catalog, submit it via CISA’s KEV Nomination Form. The submission must include a CVE ID, proof of exploitation, and clear mitigation guidance.

“CISA will continue to add vulnerabilities that meet the criteria of active exploitation,” says the agency. “We encourage every organization to prioritize these high‑risk flaws.”

CISA KEV Adobe Microsoft N‑able Vulnerability Management

← All news