CISA Adds Four Known Exploited Vulnerabilities to Catalog
Summary
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. These vulnerabilities affect Adobe Commerce, Magento, Microsoft Windows, and N-able N-central. The update reinforces the importance of CISA's Binding Operational Directive (BOD) 26-04, which mandates FCEB agencies to prioritize the remediation of these high-risk vulnerabilities.
IFF Assessment
The article highlights newly identified vulnerabilities that are actively being exploited, presenting a direct threat to organizations.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 11, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching or mitigating the four newly identified vulnerabilities added to CISA's KEV catalog, as they are confirmed to be actively exploited. This includes vulnerabilities in Adobe Commerce, Magento, Microsoft Windows, and N-able N-central. Organizations should also stay informed about CISA directives like BOD 26-04 to align with risk-based vulnerability management practices.