Threat Brief — 2026-09-09 — Four CVEs Hit CISA KEV
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog across Microsoft Windows, N-able N-central, and Adobe Commerce/Magento — all confirmed as exploited in the wild. The Windows entries are local privilege escalation flaws; the N-able issue enables pre-authentication remote code execution, and the Adobe Commerce vulnerability involves template engine injection. Separately, coverage of Microsoft's September Patch Tuesday now reports 974 CVEs — a higher figure than the 966 initially cited yesterday.
Top items
- CVE-2026-85880KEV — Microsoft Windows Advanced Local Procedure Call heap-based buffer overflow (LPE): Added to CISA KEV; actively exploited in the wild. Enables local privilege escalation. Remediation due 2026-09-22. (src: CISA KEV)
- CVE-2026-86218KEV — N-able N-central static code injection (pre-auth RCE): Added to CISA KEV; actively exploited in the wild. Allows pre-authentication remote code execution on N-central management infrastructure. Remediation due 2026-09-11. (src: CISA KEV)
- CVE-2026-81963KEV — Microsoft Windows Update Stack link following (LPE to SYSTEM): Added to CISA KEV; actively exploited in the wild. A local attacker can escalate privileges to SYSTEM via the Windows Update Stack. Remediation due 2026-09-22. (src: CISA KEV)
- CVE-2026-75650KEV — Adobe Commerce / Magento Open Source template engine injection: Added to CISA KEV; actively exploited in the wild. Improper neutralization of special elements in the template engine enables code execution on commerce storefronts. (src: CISA KEV)
- Microsoft September Patch Tuesday — revised CVE count now 974: First reported 2026-09-08 by BleepingComputer as 966 flaws including 2 actively exploited zero-days. Additional reporting now cites 974 CVEs, with 58 flagged as more likely to be exploited. Microsoft attributes accelerated discovery to AI-assisted vulnerability identification. (src: Dark Reading) · (src: Krebs on Security)
Themes
Privilege escalation remains a preferred attacker objective. Two of the four new KEV entries (CVE-2026-85880KEV and CVE-2026-81963KEV) are Windows local privilege escalation flaws, underscoring continued attacker reliance on LPE to move from initial foothold to full system compromise — particularly through Windows kernel and update stack components.
Management and e-commerce platforms under active attack. The N-able N-central and Adobe Commerce KEV additions highlight that RMM platforms and commerce storefronts remain high-value targets for pre-authentication exploitation, offering attackers both lateral movement and direct monetisation paths.
