On 8 September CISA listed four vulnerabilities as actively exploited. The one closest to online shops is in Adobe Commerce and Magento Open Source: code execution without login, rated 10.0 by Adobe, patched the day before. Next to it sit N-able N-central and two local Windows flaws.
- CVE-2026-75650 in Adobe Commerce and Magento Open Source: template engine injection, no authentication, CVSS 10.0 per Adobe. KEV deadline 11 September.
- CVE-2026-86218 in N-able N-central: pre-authentication code execution. On 6 September N-able wrote it had no confirmed exploitation; the active exploitation comes from CISA.
- CVE-2026-81963 and CVE-2026-85880 in Windows: local escalation to SYSTEM, exploitation detected per Microsoft. Deadline 22 September.
CISA gave US federal agencies three days to patch the Magento flaw. For the two Windows flaws from the same day the deadline is fourteen.
A listing in the catalog means the attacks are not theory, and the short deadline shows how urgent CISA considers it. With this flaw you feel it even more, because Adobe itself writes that it is aware of exploitation.
If you run a shop on Magento
Don't leave it for Monday. A flaw that needs no login and reaches code execution is the worst kind an online shop can be hit by. The attacker doesn't knock. They need neither an account nor any action on your side.
Adobe ships a hotfix specifically for this vulnerability, separate from the regular releases. Apply it, then look through the logs from the last few days for anything you don't recognise. If the shop is with a provider who maintains it, ask them today whether it has been done.
The other three
N-central is a tool providers use to manage other people's networks, so any flaw in it is bigger than itself. There is a nuance: on 6 September N-able wrote there were no confirmed attacks. Two days later CISA says the opposite. That is a difference in timing and in who saw what, not necessarily a contradiction.
The two Windows flaws require the attacker to already be inside. They don't open the door. They turn the guest who got in into the owner of the machine, which is why they are favourites as a second step after someone has entered another way.
The order is clear: the shop today, N-central today, Windows with the monthly update, only this month without delay.