การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Vulnerability

CISA Expands KEV Catalog with Adobe, Microsoft, and N-able Flaws

FORTSECURE GLOBAL· 2026-09-10🛰 CISA Cybersecurity Advisories
#Vulnerability#Microsoft#Cyber Risk#Application Security

CISA has flagged four actively abused security flaws across Adobe Commerce, Microsoft Windows, and N-able N-central platforms.

CISA has incorporated four additional vulnerabilities into its Known Exploited Vulnerabilities (KEV) Catalog, emphasizing active exploitation by cyber threat groups against enterprise platforms. The latest inclusions affect Adobe Commerce and Magento, Microsoft Windows operating systems, and N-able N-central management software.

The identified vulnerabilities introduce substantial risk to organizations. CVE-2026-75650 involves improper neutralization in Adobe Commerce and Magento template engines, exposing e-commerce sites to arbitrary code execution. Within Microsoft Windows environments, attackers are leveraging CVE-2026-81963 (a link-following flaw) and CVE-2026-85880 (a heap-based buffer overflow) to escalate privileges and disrupt system integrity. Furthermore, CVE-2026-86218 exposes N-able N-central to static code injection, posing significant supply-chain risks for managed service providers.

Risk Mitigation Strategies

Security teams must promptly counter active weaponization of these core enterprise components by implementing targeted security controls:

  • Apply Timely Vendor Fixes: Deploy the latest cumulative updates from Microsoft and patches from Adobe and N-able to neutralize known exploit chains.
  • Strengthen Monitoring on Management Tools: Enhance endpoint detection and telemetry collection for remote management platforms such as N-central to detect anomalous script executions.
  • Harden Web Applications: Deploy Web Application Firewalls (WAF) ahead of Adobe Commerce platforms to inspect and block template injection payloads targeting web storefronts.

แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Tue, 08 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: CISA Cybersecurity Advisories

เผยแพร่ครั้งแรก: Tue, 08 Sep 26 12:00:00 +0000

บทความต้นฉบับ: https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog