CISA's list that day

8 September 2026

On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Adobe Commerce and Magento, Microsoft Windows and N-able N-central. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-86218Static Code InjectionN-able N-centralPatch nowForensic triage required by CISA0.13
CVE-2026-75650Improper Neutralization of Special Elements Used in a Template EngineAdobe Commerce and MagentoPatch nowForensic triage required by CISA0.04
CVE-2026-85880Heap-Based Buffer OverflowMicrosoft WindowsPatch soon0.04
CVE-2026-81963Link FollowingMicrosoft WindowsPatch soon0.00

Other changes that day

  1. CVE-2025-14733 WatchGuard FireboxRansomware use: Unknown to Known.