CVE Digest

CVE Digest — September 8, 2026

  • Security Bulletin
4 CVE 4 KEV

4 vulnerabilities were added to the CISA KEV catalog on September 8, 2026 and published on NVD. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.

CVEProductCVSSSeveritySummaryReferences
CVE-2026-75650 KEVAdobe Commerce and MagentoUnknownAdobe Commerce and Magento Open Source have a template engine injection issue caused by improper neutralization of special elements, enabling arbitrary code execution. This CVE is in CISA KEV; apply vendor mitigations and follow BOD 26-04 guidance.
CVE-2026-81963 KEVMicrosoft WindowsUnknownMicrosoft Windows Update Stack has a link following flaw that lets a local attacker escalate privileges to SYSTEM. This CVE is in CISA KEV; apply vendor mitigations and follow BOD 26-04 guidance.
CVE-2026-86218 KEVN-able N-centralUnknownN-able N-central has a static code injection vulnerability that can lead to pre-authentication remote code execution. This CVE is in CISA KEV; apply vendor mitigations and follow BOD 26-04 guidance.
CVE-2026-85880 KEVMicrosoft WindowsUnknownMicrosoft Windows Advanced Local Procedure Call has a heap-based buffer overflow that enables local privilege escalation. This CVE is in CISA KEV; apply vendor mitigations and follow BOD 26-04 guidance.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.