CVE Digest — September 8, 2026
4 CVE
4 KEV
4 vulnerabilities were added to the CISA KEV catalog on September 8, 2026 and published on NVD. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-75650 KEV | Adobe Commerce and Magento | – | Unknown | Adobe Commerce and Magento Open Source have a template engine injection issue caused by improper neutralization of special elements, enabling arbitrary code execution. This CVE is in CISA KEV; apply vendor mitigations and follow BOD 26-04 guidance. | |
| CVE-2026-81963 KEV | Microsoft Windows | – | Unknown | Microsoft Windows Update Stack has a link following flaw that lets a local attacker escalate privileges to SYSTEM. This CVE is in CISA KEV; apply vendor mitigations and follow BOD 26-04 guidance. | |
| CVE-2026-86218 KEV | N-able N-central | – | Unknown | N-able N-central has a static code injection vulnerability that can lead to pre-authentication remote code execution. This CVE is in CISA KEV; apply vendor mitigations and follow BOD 26-04 guidance. | |
| CVE-2026-85880 KEV | Microsoft Windows | – | Unknown | Microsoft Windows Advanced Local Procedure Call has a heap-based buffer overflow that enables local privilege escalation. This CVE is in CISA KEV; apply vendor mitigations and follow BOD 26-04 guidance. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.