Multiple Critical CVEs Target Adobe and Microsoft Products

Multiple Critical CVEs Target Adobe and Microsoft Products

First seen 8 Sep 2026, 20:43 UTC Redpacketsecurity 77.2

Article Content

Browse articles
ThreatCluster

Four critical vulnerabilities have been disclosed affecting Adobe Commerce and Microsoft Windows systems. CVE-2026-75650 in Adobe Commerce allows arbitrary code execution without user interaction, impacting online retailers and B2B storefronts. Microsoft faces two vulnerabilities: CVE-2026-85880, a heap-based buffer overflow in Windows ALPC, and CVE-2026-81963, an improper link resolution in Windows Update Stack, both enabling local privilege escalation. Additionally, CVE-2026-86218 in N-able N-central allows pre-auth remote code execution, threatening managed service providers. All vulnerabilities are actively exploited, requiring immediate remediation. CISA has added these CVEs to its KEV catalog, emphasizing their urgency.

Key Points: • CVE-2026-75650 allows arbitrary code execution in Adobe Commerce. • CVE-2026-85880 and CVE-2026-81963 enable local privilege escalation in Microsoft Windows. • CVE-2026-86218 allows pre-auth remote code execution in N-able N-central.

Ask AI about this cluster

Timeline

2026-09-06
CVE-2026-86218 published
N-able N-central vulnerability disclosed, allowing pre-auth remote code execution.
Redpacketsecurity
2026-09-07
CVE-2026-75650 published
Adobe Commerce vulnerability disclosed, enabling arbitrary code execution.
Redpacketsecurity
2026-09-08
CVE-2026-85880 added to CISA KEV
Active exploitation confirmed for Windows ALPC vulnerability, requiring urgent patching.
Redpacketsecurity
2026-09-08
CVE-2026-81963 added to CISA KEV
Active exploitation confirmed for Windows Update Stack vulnerability, necessitating immediate action.
Redpacketsecurity
2026-09-08
CVE-2026-86218 added to CISA KEV
Active exploitation confirmed for N-central vulnerability, posing a critical risk to service providers.
Redpacketsecurity