Pierluigi Paganini
September 10, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
CVE-2026-75650 (CVSS score of 10.0) is an Adobe Commerce and Magento improper neutralization of special elements in a template engine vulnerability that can lead to unauthenticated remote code execution. The flaw, tracked as StyleSmuggler, has been actively exploited in the wild since September 4, with attackers reportedly using it to deploy web shells and backdoors, Sansec researchers warned. The flaw lets unauthenticated attackers run code on vulnerable online stores. Sansec researchers say it affects current Magento Open Source releases, including 2.4.7, 2.4.8 and 2.4.9. According to the experts, exploitation began on September 4. StyleSmuggler works by placing PHP code into Magento’s templating path and later causing the platform to evaluate it. The first stage creates or poisons a record, while the second stage turns a routine email-rendering process into remote code execution.
CVE-2026-81963 (CVSS score of 7.8) is a Microsoft Windows Update Stack link-following vulnerability that allows a local attacker to gain higher privileges. Microsoft has confirmed that the flaw is being actively exploited in the wild. The vulnerability lets an attacker follow a malicious link and escalate privileges. It is the first Update Stack vulnerability that Microsoft has confirmed attackers are actively exploiting.
CVE-2026-85880 (CVSS score of 7.8) is a Microsoft Windows heap-based buffer overflow in the Advanced Local Procedure Call (ALPC) component that allows a local attacker to elevate privileges to SYSTEM. Microsoft has confirmed active exploitation of the vulnerability.
CVE-2026-86218 (CVSS score of 10.0) – N-able N-central static code injection vulnerability that allows a pre-authenticated remote attacker to execute arbitrary code on vulnerable systems. The flaw has been exploited in the wild and N-able released an emergency hotfix to address it.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the Windows flaws by September 22, while the remaining must be addressed by September 11, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)