we_are_coded.by CODE · The world, decoded
БГ
CISA

A Magento flaw rated 10 entered the catalog of exploited vulnerabilities, with three days to patch

CISA · event date: 8 September 2026Security

On 8 September CISA listed four vulnerabilities as actively exploited. The one closest to online shops is in Adobe Commerce and Magento Open Source: code execution without login, rated 10.0 by Adobe, patched the day before. Next to it sit N-able N-central and two local Windows flaws.

In short
  • CVE-2026-75650 in Adobe Commerce and Magento Open Source: template engine injection, no authentication, CVSS 10.0 per Adobe. KEV deadline 11 September.
  • CVE-2026-86218 in N-able N-central: pre-authentication code execution. On 6 September N-able wrote it had no confirmed exploitation; the active exploitation comes from CISA.
  • CVE-2026-81963 and CVE-2026-85880 in Windows: local escalation to SYSTEM, exploitation detected per Microsoft. Deadline 22 September.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

CISA gave US federal agencies three days to patch the Magento flaw. For the two Windows flaws from the same day the deadline is fourteen.

A listing in the catalog means the attacks are not theory, and the short deadline shows how urgent CISA considers it. With this flaw you feel it even more, because Adobe itself writes that it is aware of exploitation.

The facts: on 8 September 2026 CISA added four vulnerabilities to the KEV catalog. CVE-2026-75650 in Adobe Commerce and Magento Open Source is improper neutralisation of special elements in a template engine, allowing arbitrary code execution; the deadline is 11 September. In bulletin APSB26-146 of 7 September Adobe gives it CVSS 10.0, states that no authentication is required and that it is aware of exploitation in the wild, and releases a hotfix for affected versions of Adobe Commerce (2.4.4 to 2.4.9 with the August releases and earlier), Adobe Commerce B2B and Magento Open Source (2.4.6 to 2.4.9). CVE-2026-86218 in N-able N-central is static code injection with possible pre-authentication code execution, deadline 11 September; N-able shipped the fix in N-central 2026.3 Hotfix 4 (build 2026.3.1.14) on 6 September and wrote at the time that it had no confirmation of exploitation. CVE-2026-81963 (Windows Update Stack, link following) and CVE-2026-85880 (Windows ALPC, heap-based buffer overflow) allow local privilege escalation to SYSTEM; Microsoft marks both as exploitation detected in its bulletins of 8 September. The deadline for both is 22 September.

If you run a shop on Magento

Don't leave it for Monday. A flaw that needs no login and reaches code execution is the worst kind an online shop can be hit by. The attacker doesn't knock. They need neither an account nor any action on your side.

Adobe ships a hotfix specifically for this vulnerability, separate from the regular releases. Apply it, then look through the logs from the last few days for anything you don't recognise. If the shop is with a provider who maintains it, ask them today whether it has been done.

The attacker needs no account. Only an unpatched shop.

The other three

N-central is a tool providers use to manage other people's networks, so any flaw in it is bigger than itself. There is a nuance: on 6 September N-able wrote there were no confirmed attacks. Two days later CISA says the opposite. That is a difference in timing and in who saw what, not necessarily a contradiction.

The two Windows flaws require the attacker to already be inside. They don't open the door. They turn the guest who got in into the owner of the machine, which is why they are favourites as a second step after someone has entered another way.

The order is clear: the shop today, N-central today, Windows with the monthly update, only this month without delay.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog (official catalog)→Adobe - Security update available for Adobe Commerce, APSB26-146, 07.09.2026→N-able - N-central 2026.3 Hotfix 4, CVE-2026-86218, 06.09.2026→Microsoft MSRC - CVE-2026-81963, 08.09.2026→Microsoft MSRC - CVE-2026-85880, 08.09.2026
Original: https://wearecoded.com/en/articles/kev-magento-cve-2026-75650-tri-dni.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news