Incident timing: Advisory released September 8, 2026; covers multiple vulnerabilities.
Official advisory
CISA's September 8 notice adds four issues to its Known Exploited Vulnerabilities catalog: CVE-2026-75650, CVE-2026-81963, CVE-2026-85880, and CVE-2026-86218. The affected products include Adobe Commerce and Magento, Microsoft Windows, and N-able N-central.
Related but distinct coverage
This is a multi-product government advisory, not an additional victim of a single cyberattack. The Windows issue CVE-2026-85880 also appears in research covered by our separate BlueMoon brief; these should not be counted as two independent incidents.
Business context
Teams can use the catalog to prioritize review of affected software in their estate. Version-specific fixes and investigation steps must come from the current catalog and vendor advisories, rather than this short news summary.
Source & attribution
Read the original reporting at CISAAI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.