[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CYBER WATCH / Vulnerabilities

CISA flags exploited flaws affecting enterprise software and remote management

CISA's September 8 alert adds four exploited vulnerabilities spanning Adobe Commerce and Magento, Microsoft Windows, and N-able N-central. The advisory is a patch-prioritization signal for affected deployments, not a single breach report. One Windows issue also appears in separate reporting on the BlueMoon exploit chain.

All updates
Reported Officially confirmedPublished Date not recorded

Incident timing: Advisory released September 8, 2026; covers multiple vulnerabilities.

Official advisory

CISA's September 8 notice adds four issues to its Known Exploited Vulnerabilities catalog: CVE-2026-75650, CVE-2026-81963, CVE-2026-85880, and CVE-2026-86218. The affected products include Adobe Commerce and Magento, Microsoft Windows, and N-able N-central.

This is a multi-product government advisory, not an additional victim of a single cyberattack. The Windows issue CVE-2026-85880 also appears in research covered by our separate BlueMoon brief; these should not be counted as two independent incidents.

Business context

Teams can use the catalog to prioritize review of affected software in their estate. Version-specific fixes and investigation steps must come from the current catalog and vendor advisories, rather than this short news summary.

Source & attribution

Read the original reporting at CISA

AI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.

Editorial policy & corrections