Critical Remote Code Execution Flaws in Adobe Commerce, Microsoft Windows, and N‑able N‑central Added to CISA KEV Catalog
What It Is – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed four actively‑exploited vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog:
- CVE‑2026‑75650 – Adobe Commerce/Magento “StyleSmuggler” RCE (CVSS 10.0)
- CVE‑2026‑81963 – Windows Update Stack link‑following privilege escalation (CVSS 7.8)
- CVE‑2026‑85880 – Windows ALPC heap‑based buffer overflow privilege escalation (CVSS 7.8)
- CVE‑2026‑86218 – N‑able N‑central static‑code injection RCE (CVSS 10.0)
Exploitability – All four are confirmed to be exploited in the wild. The Adobe flaw has been used to plant web shells on e‑commerce sites since Sept 4 2026; Microsoft and N‑able issues are also being leveraged by active threat actors.
Affected Products – Adobe Commerce & Magento (Open Source 2.4.7‑2.4.9), Microsoft Windows (all supported releases), and N‑able N‑central management appliances.
Why It Matters for Trust & Control Assurance
- Vulnerability Management – Demonstrates the need for continuous monitoring of known‑exploited flaws and rapid evidence of remediation.
- Audit Readiness – Organizations that can produce verifiable patch‑deployment logs satisfy a core control objective across SOC 2, ISO 27001, NIST CSF 2.0 and others.
- Defensible Evidence – Mapping these KEV entries to your control framework shows due‑diligence to regulators and enterprise buyers who demand a transparent security posture.
Recommended Actions
- Ingest the four CVEs into your vulnerability‑scanning tool and prioritize remediation based on CVSS 10.0 severity.
- Verify that the emergency hot‑fixes from Microsoft, Adobe, and N‑able have been applied across all affected assets.
- Capture patch‑deployment timestamps and retain them as audit evidence for control‑objective reporting.
- Update your asset inventory to flag any legacy systems that cannot be patched and consider compensating controls.
Source: Security Affairs – CISA adds Microsoft Windows, N‑able N‑central, and Adobe flaws to KEV catalog