CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA Adds Four Known Exploited Vulnerabilities to Catalog

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6742

As cited

Copy frozen at (site build).

vulnerabilities

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog after confirming active exploitation in the wild: CVE-2026-75650 affecting Adobe Commerce and Magento, CVE-2026-81963 and CVE-2026-85880 in Microsoft Windows, and CVE-2026-86218 in N-able N-central. Federal agencies must prioritize patching these flaws under Binding Operational Directive 26-04, and CISA encourages all organizations to treat them as high-priority remediation targets.

Why it matters: Federal civilian agencies face mandatory patching deadlines for these actively exploited flaws; all other organizations should treat these four CVEs as urgent given confirmed threat actor use.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog after confirming active exploitation in the wild: CVE-2026-75650 affecting Adobe Commerce and Magento, CVE-2026-81963 and CVE-2026-85880 in Microsoft Windows, and CVE-2026-86218 in N-able N-central. Federal agencies must prioritize patching these flaws under Binding Operational Directive 26-04, and CISA encourages all organizations to treat them as high-priority remediation targets.

Why it matters: Federal civilian agencies face mandatory patching deadlines for these actively exploited flaws; all other organizations should treat these four CVEs as urgent given confirmed threat actor use.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary