Visualização normal

Ontem — 10 de Setembro de 2026Cybersecurity News

U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog

10 de Setembro de 2026, 05:06

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
  • CVE-2026-81963 Microsoft Windows Link Following Vulnerability  
  • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability 
  • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability 

CVE-2026-75650 (CVSS score of 10.0) is an Adobe Commerce and Magento improper neutralization of special elements in a template engine vulnerability that can lead to unauthenticated remote code execution. The flaw, tracked as StyleSmuggler, has been actively exploited in the wild since September 4, with attackers reportedly using it to deploy web shells and backdoors, Sansec researchers warned. The flaw lets unauthenticated attackers run code on vulnerable online stores. Sansec researchers say it affects current Magento Open Source releases, including 2.4.7, 2.4.8 and 2.4.9. According to the experts, exploitation began on September 4. StyleSmuggler works by placing PHP code into Magento’s templating path and later causing the platform to evaluate it. The first stage creates or poisons a record, while the second stage turns a routine email-rendering process into remote code execution.

CVE-2026-81963 (CVSS score of 7.8) is a Microsoft Windows Update Stack link-following vulnerability that allows a local attacker to gain higher privileges. Microsoft has confirmed that the flaw is being actively exploited in the wild. The vulnerability lets an attacker follow a malicious link and escalate privileges. It is the first Update Stack vulnerability that Microsoft has confirmed attackers are actively exploiting.

CVE-2026-85880 (CVSS score of 7.8) is a Microsoft Windows heap-based buffer overflow in the Advanced Local Procedure Call (ALPC) component that allows a local attacker to elevate privileges to SYSTEM. Microsoft has confirmed active exploitation of the vulnerability.

CVE-2026-86218 (CVSS score of 10.0) – N-able N-central static code injection vulnerability that allows a pre-authenticated remote attacker to execute arbitrary code on vulnerable systems. The flaw has been exploited in the wild and N-able released an emergency hotfix to address it.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the Windows flaws by September 22, while the remaining must be addressed by September 11, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

Antes de ontemCybersecurity News

U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog

5 de Agosto de 2026, 12:25

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2026-9198 (CVSS score of 9.8) IBM Langflow Code Injection Vulnerability
  • CVE-2026-18556 (CVSS score of 8.2) N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
  • CVE-2026-34486 (CVS score of 7.5) Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

The first issue added to the catalog, tracked as CVE-2026-9198, is a critical issue in IBM Langflow OSS versions 1.0.0–1.10.0 that lets unauthenticated attackers gain superuser access and execute arbitrary code, leading to full remote code execution on default deployments.

The second issue, tracked as CVE-2026-18556, is an authentication bypass flaw in N-able N-central that allows attackers to access affected systems without valid credentials, impacting versions through 2026.1.

The last issue added to the KeV catalog is CVE-2026-34486, a flaw in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 that can bypass the EncryptInterceptor, exposing sensitive data.

Researchers linked the exploitation of CVE-2026-34486 to a Chinese-speaking threat actor that used an AI-powered autonomous hacking agent based on DeepSeek to identify and exploit internet-facing vulnerabilities. When one attack path failed, the AI independently searched for alternative flaws, while the attackers also carried out manual exploitation of vulnerabilities in Citrix NetScaler, Apache Tomcat, Marimo, and IKE VPN systems.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaws by August 7, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

  • ✇Security Affairs
  • U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog Pierluigi Paganini
    U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-18577 (CVSS 8.2) is an authentication bypass flaw caused by an incomplete fix for a previous vulnerability tracked as CVE-2026-18556. It allows remot
     

U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog

4 de Agosto de 2026, 08:02

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8.2), to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2026-18577 (CVSS 8.2) is an authentication bypass flaw caused by an incomplete fix for a previous vulnerability tracked as CVE-2026-18556. It allows remote attackers to take over accounts and gain administrative access to vulnerable N-able N-central servers. From there, they can use the built-in Take Control feature to move into managed endpoints and establish persistent access.

The company confirmed that a limited number of customers have been identified to be impacted by this, and, for those impacted customers, N‑able support has directly engaged. If you’re a customer who is not running the most recent version of N‑central, we strongly encourage you to upgrade to 2026.3.1.7.

Organizations can check for compromise by looking for a suspicious svchost.exe file in users’ Documents folders, a registered Cloudflared service, or inbound firewall connections from the listed IP addresses:

  • 173[.]249[.]252[.]200
  • 87[.]249[.]138[.]34
  • 37[.]19[.]210[.]32
  • 68[.]235[.]46[.]214. 

If any indicators are found, they should immediately contact N-able support and their security team.

Huntress researchers observed attackers exploiting CVE-2026-18577 against multiple organizations, although the activity does not yet appear to be widespread. After gaining access, attackers conducted reconnaissance, targeted domain controllers, enumerated processes, and moved laterally across networks.

“As Huntress continues our investigation and analysis of activity targeting vulnerable N-able N-central environments, we discovered that the four IPs N-able initially flagged as malicious are actually Mullvad or NordVPN VPN exit nodes.” reads the Huntress’s report. “Notably, among the original IPs, we have seen substantial traffic with 87.249.138[.]34 directly attributed to NordVPN, as well as substantial traffic with 37.19.210[.]32 directly attributed to Mullvad VPN. 37.19.210[.]32 has been previously abused for bruteforcing, spam, and other nefarious activity prior to this incident.”

N-able confirmed that a limited number of customers were compromised, highlighting the ongoing abuse of remote monitoring and management (RMM) platforms to gain persistent access.

Huntress warned that more than half (55.6%) of the reachable N-central cloud servers used by its partners and customers remained unpatched against CVE-2026-18577, leaving them exposed to exploitation. The company also noted that N-able added two more malicious IP addresses to its indicators of compromise and said it will continue investigating the attacks and provide updates as new findings emerge.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerability by the end of this week, on August 6, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

❌
❌