Skip to content
CISA Adds Critical Vulnerabilities to KEV Catalog Amid Active Exploitation

CISA Adds Critical Vulnerabilities to KEV Catalog Amid Active Exploitation

First seen 10 Sep 2026, 19:50 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 10, 2026 at 21:16 UTC
  • CISA added multiple critical vulnerabilities to its KEV catalog on September 10, 2026.
  • CVE-2026-75650 allows unauthenticated remote code execution in Adobe Commerce, exploited since September 4.
  • CVE-2026-20079 in Cisco products enables unauthenticated remote access, rated CVSS 10.0.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including critical flaws in Microsoft Windows, Adobe, N-able, Cisco, Google Chromium, Fortinet, and Citrix. Notably, CVE-2026-75650, a critical Adobe Commerce vulnerability, allows unauthenticated remote code execution and has been actively exploited since September 4. Other vulnerabilities include CVE-2026-81963 and CVE-2026-85880 in Microsoft Windows, both allowing privilege escalation and confirmed to be exploited in the wild. Cisco's CVE-2026-20079 is an authentication bypass flaw with a CVSS score of 10.0, enabling remote attackers to gain root access. Fortinet's CVE-2025-25249 and Citrix's CVE-2026-19490 also pose significant risks, with active exploitation confirmed. CISA mandates federal agencies to address these vulnerabilities promptly to safeguard their networks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-01-13
CVE-2025-25249 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-04
Exploitation of CVE-2026-75650 begins
Attackers started exploiting the Adobe Commerce vulnerability to deploy web shells and backdoors.
Securityaffairs.Co
2026-09-06
CVE-2026-86218 published
N-able N-central static code injection vulnerability disclosed, allowing remote code execution.
Securityaffairs.Co
2026-09-07
CVE-2026-75650 added to CISA KEV
CISA confirmed active exploitation of the Adobe Commerce vulnerability in its KEV catalog.
Securityaffairs.Co
2026-09-08
CVE-2026-81963 and CVE-2026-85880 added to CISA KEV
Microsoft Windows vulnerabilities confirmed to be actively exploited, with privilege escalation capabilities.
Securityaffairs.Co
2026-09-09
CVE-2026-19490 and CVE-2026-87491 added to CISA KEV
Citrix and Google Chromium vulnerabilities listed for active exploitation, posing high risks to users.
Securityaffairs.Co
2026-09-10
CISA issues urgent advisory
CISA mandates federal agencies to address newly listed vulnerabilities to protect networks.
Securityaffairs.Co

More articles in this cluster (2)

Following this threat?

Track Cisco and CVE-2025-25249 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed