CISA's list that day
8 September 2026
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Adobe Commerce and Magento, Microsoft Windows and N-able N-central. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-86218Static Code Injection | N-able N-central | Patch nowForensic triage required by CISA | 0.13 | ||
| CVE-2026-75650Improper Neutralization of Special Elements Used in a Template Engine | Adobe Commerce and Magento | Patch nowForensic triage required by CISA | 0.04 | ||
| CVE-2026-85880Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.04 | ||
| CVE-2026-81963Link Following | Microsoft Windows | Patch soon | 0.00 |