CISA Adds Four Known Exploited Vulnerabilities to Catalog

Summary

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. These vulnerabilities affect Adobe Commerce, Magento, Microsoft Windows, and N-able N-central. The update reinforces the importance of CISA's Binding Operational Directive (BOD) 26-04, which mandates FCEB agencies to prioritize the remediation of these high-risk vulnerabilities.

IFF Assessment

FOE

The article highlights newly identified vulnerabilities that are actively being exploited, presenting a direct threat to organizations.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 11, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching or mitigating the four newly identified vulnerabilities added to CISA's KEV catalog, as they are confirmed to be actively exploited. This includes vulnerabilities in Adobe Commerce, Magento, Microsoft Windows, and N-able N-central. Organizations should also stay informed about CISA directives like BOD 26-04 to align with risk-based vulnerability management practices.

Read Full Story →