September 9, 2026 — Small Business Cyber Watch
Today’s priority: Review the newest entries in CISA’s authoritative catalog of vulnerabilities known to be exploited in the wild. The most recent catalog additions shown below are dated September 8, 2026.
Adobe Commerce and Magento: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
CVE-2026-75650 · Added by CISA September 8, 2026
What changed: Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.
What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 11, 2026.
Microsoft Windows: Microsoft Windows Link Following Vulnerability
CVE-2026-81963 · Added by CISA September 8, 2026
What changed: Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.
What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 22, 2026.
N-able N-central: N-able N-central Static Code Injection Vulnerability
CVE-2026-86218 · Added by CISA September 8, 2026
What changed: N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.
What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 11, 2026.
Microsoft Windows: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
CVE-2026-85880 · Added by CISA September 8, 2026
What changed: Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.
What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 22, 2026.
Google Chromium V8: Google Chromium V8 Type Confusion Vulnerability
CVE-2026-85046 · Added by CISA September 4, 2026
What changed: Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.
What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 18, 2026.
Small-business action list
- Ask your IT provider whether any affected product is in your environment.
- Prioritize internet-facing, remote-access, identity, and backup systems.
- Apply vendor updates or mitigations after appropriate testing.
- Review privileged-account activity and confirm recoverable backups.
Verified source: CISA Known Exploited Vulnerabilities Catalog.
This edition is prepared automatically from CISA’s published data and provides general awareness, not an assessment of any specific organization.
