HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Remote Code Execution Flaws in Adobe Commerce, Microsoft Windows, and N‑able N‑central Added to CISA KEV Catalog

CISA has listed four actively‑exploited vulnerabilities—Adobe Commerce’s StyleSmuggler RCE, two Windows privilege‑escalation bugs, and an N‑able N‑central code‑injection flaw—in its KEV catalog. Enterprises must prove rapid remediation and audit‑ready evidence to satisfy multiple control frameworks.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Critical Remote Code Execution Flaws in Adobe Commerce, Microsoft Windows, and N‑able N‑central Added to CISA KEV Catalog

What It Is – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed four actively‑exploited vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE‑2026‑75650 – Adobe Commerce/Magento “StyleSmuggler” RCE (CVSS 10.0)
  • CVE‑2026‑81963 – Windows Update Stack link‑following privilege escalation (CVSS 7.8)
  • CVE‑2026‑85880 – Windows ALPC heap‑based buffer overflow privilege escalation (CVSS 7.8)
  • CVE‑2026‑86218 – N‑able N‑central static‑code injection RCE (CVSS 10.0)

Exploitability – All four are confirmed to be exploited in the wild. The Adobe flaw has been used to plant web shells on e‑commerce sites since Sept 4 2026; Microsoft and N‑able issues are also being leveraged by active threat actors.

Affected Products – Adobe Commerce & Magento (Open Source 2.4.7‑2.4.9), Microsoft Windows (all supported releases), and N‑able N‑central management appliances.

Why It Matters for Trust & Control Assurance

  • Vulnerability Management – Demonstrates the need for continuous monitoring of known‑exploited flaws and rapid evidence of remediation.
  • Audit Readiness – Organizations that can produce verifiable patch‑deployment logs satisfy a core control objective across SOC 2, ISO 27001, NIST CSF 2.0 and others.
  • Defensible Evidence – Mapping these KEV entries to your control framework shows due‑diligence to regulators and enterprise buyers who demand a transparent security posture.

Recommended Actions

  1. Ingest the four CVEs into your vulnerability‑scanning tool and prioritize remediation based on CVSS 10.0 severity.
  2. Verify that the emergency hot‑fixes from Microsoft, Adobe, and N‑able have been applied across all affected assets.
  3. Capture patch‑deployment timestamps and retain them as audit evidence for control‑objective reporting.
  4. Update your asset inventory to flag any legacy systems that cannot be patched and consider compensating controls.

Source: Security Affairs – CISA adds Microsoft Windows, N‑able N‑central, and Adobe flaws to KEV catalog

📰 Original Source
https://securityaffairs.com/198802/hacking/u-s-cisa-adds-microsoft-windows-n-able-n-central-and-adobe-flaws-to-its-known-exploited-vulnerabilities-catalog.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →