Adobe Commerce / Magento Open Source · N-able N-central · Microsoft Windows Update Stack
Date: 2026-09-09 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
CISA added four vulnerabilities to the KEV Catalog, including the actively exploited Magento/Adobe Commerce flaw CVE-2026-75650, N-able N-central pre-authentication RCE CVE-2026-86218, and two Microsoft Windows privilege-escalation vulnerabilities. Microsoft’s September Patch Tuesday is unusually large, with more than 960 reported fixes and two vulnerabilities exploited in the wild. German CERT-Bund advisories also highlight new exposure in Roundcube, SAP, Red Hat Directory Server and other enterprise products.
Critical Vulnerabilities
CVE-2026-75650 — Adobe Commerce / Magento Open Source
- Severity: CVSS 10.0
- EPSS: 0 — no EPSS exploitation probability currently reported
- Technical detail: Improper neutralization of special elements in a template engine allows a remote, unauthenticated attacker to execute arbitrary code with administrator-level privileges. Affected Magento and Adobe Commerce deployments are commonly internet-facing and may process attacker-controlled storefront or administrative input.
- Exploitation status: STATUS CHANGE — confirmed active exploitation and added to the CISA KEV Catalog. Reporting links the StyleSmuggler campaign to deployment of a Rust backdoor and PHP web shells.
- Remediation: Apply Adobe’s emergency security update immediately, prioritizing internet-facing stores. Hunt for modified payment or template files, new administrator accounts, web shells, suspicious cron jobs and unexpected outbound connections. CISA remediation is due by 2026-09-11.
CVE-2026-86218 — N-able N-central
- Severity: CVSS 10.0
- EPSS: 0 — no EPSS exploitation probability currently reported
- Technical detail: A static code injection issue permits pre-authentication remote code execution against affected N-central servers. Because N-central can issue privileged commands and policies to managed endpoints, compromise of the management server could enable broad downstream control.
- Exploitation status: STATUS CHANGE — added to CISA KEV based on evidence of active exploitation. Earlier vendor communications described exploitation as unconfirmed, so incident confidence and scope remain under investigation.
- Remediation: Upgrade to N-central
2026.3.1.14or later and apply all required hotfixes. Restrict administrative access to trusted networks, review server and agent activity, and investigate unexpected scripts, policies, commands or endpoint changes. CISA remediation is due by 2026-09-11.
CVE-2026-81963 — Microsoft Windows Update Stack
- Severity: Not supplied; CISA KEV-listed
- EPSS: 0 — no EPSS exploitation probability currently reported
- Technical detail: A link-following vulnerability in the Windows Update Stack allows a local attacker to escalate privileges to SYSTEM. Exploitation requires local execution or an existing foothold, but successful use can provide full host control and support follow-on credential theft or lateral movement.
- Exploitation status: NEW — added to the CISA KEV Catalog as actively exploited.
- Remediation: Deploy Microsoft’s September 2026 security updates across supported Windows systems, with priority for administrator workstations and servers used for software distribution or privileged administration. CISA remediation is due by 2026-09-22.
CVE-2026-85880 — Microsoft Windows Advanced Local Procedure Call
- Severity: Not supplied; CISA KEV-listed
- EPSS: 0 — no EPSS exploitation probability currently reported
- Technical detail: A heap-based buffer overflow in the Windows Advanced Local Procedure Call component allows local privilege escalation. The vulnerability can be used after initial access to elevate an attacker to SYSTEM and bypass normal user-level restrictions.
- Exploitation status: NEW — added to the CISA KEV Catalog as actively exploited.
- Remediation: Apply the September 2026 Windows cumulative updates. Confirm successful deployment on high-value endpoints and servers, and investigate suspicious process elevation, service creation and token manipulation. CISA remediation is due by 2026-09-22.
CVE-2026-69595 — Microsoft Windows Services for NFS ONCRPC XDR Driver
- Severity: CVSS 9.8
- EPSS: 0 — no EPSS exploitation probability currently reported
- Technical detail: A use-after-free vulnerability in the Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. Exposure is most relevant where NFS services are enabled and reachable from untrusted or broadly accessible network segments; the supplied data does not confirm exploitation.
- Exploitation status: NEW — published within the reporting window; no exploitation reported.
- Remediation: Apply Microsoft’s September updates and identify systems running Services for NFS. Disable unnecessary NFS functionality and restrict access to trusted networks while deployment is pending.
ONGOING
CVE-2026-86060(MikroTik RouterOS): active exploitation and persistence-account creation continue; patch immediately and investigate accounts, SSH keys and configuration changes.CVE-2026-63520(Microsoft SharePoint): exploitation and public PoC remain reported; verify patching and hunt for web shells.CVE-2026-19490(Citrix NetScaler): attacks remain reported; restrict management interfaces and complete remediation.CVE-2026-81578/CVE-2026-82078(PaperCut): exploitation remains reported; remediate before the 2026-09-14 KEV deadline.CVE-2026-85046(Chromium V8),CVE-2026-83548/CVE-2026-83549(SonicWall SMA1000) andCVE-2026-0768(Langflow): remediation remains required.
European Advisories
WID-SEC-2026-3223 (Adobe Magento): covered in Critical Vulnerabilities.
CERT-Bund published a new high-severity Roundcube advisory covering multiple vulnerabilities that may enable security-control bypass, information disclosure, data manipulation and cross-site scripting by remote unauthenticated attackers. Patch internet-facing mail systems and review webmail, authentication and mailbox activity.
WID-SEC-2026-3220 consolidates the September 2026 SAP Patch Day vulnerabilities, including code execution, privilege escalation, security-control bypass, information disclosure, SQL injection and denial-of-service impacts. Apply the SAP security updates and prioritize internet-accessible or broadly reachable SAP components; the previously detailed SAP kernel issues remain particularly important.
New CERT-Bund advisories also cover Red Hat Directory Server/Enterprise Linux 389-ds-base, IBM App Connect Enterprise, JetBrains YouTrack and Samsung Android. Review applicability based on asset inventory and prioritize systems providing identity, integration or administrative services.
WID-SEC-2026-3230 (strongSwan) affects authenticated remote attackers and may permit security-control bypass, information disclosure or code execution. Validate VPN gateway exposure and apply the vendor fixes.
Active Threats and Campaigns
- ClearFake WebDAV infection chain — NEW: Cisco Talos reports a delivery chain using compromised or deceptive websites and WebDAV to deliver Amatera stealer, ZigCryptoStealer and NetSupport Manager. The activity is assessed as financially motivated rather than organization-specific. Monitor browser-launched WebDAV activity, unusual script execution, credential theft indicators and unauthorized remote-management software. Cisco Talos
- ClickFix browser-based cryptocurrency theft — NEW: Attackers are abusing the Google Visualization API and public Google Sheets to retrieve obfuscated JavaScript and inject it into browser sessions. Block or monitor suspicious browser developer-console instructions, unexpected script injection and outbound requests to unapproved Google-hosted content. Cisco Talos
- AI-enabled attack automation — STATUS CHANGE: GTIG reports movement from prompt-based abuse toward agentic workflows that automate reconnaissance, planning and credential theft. Review controls for cloud identities, AI integrations and high-volume automated authentication activity. Google Threat Intelligence
- Magento StyleSmuggler — ONGOING: Active exploitation continues; perform compromise hunting after patching.
Security News and Context
- Microsoft’s September 2026 Patch Tuesday is the largest reported to date, with more than 960 fixes and two actively exploited vulnerabilities. SANS ISC
- The EU Cyber Resilience Act’s vulnerability-reporting requirements take effect on September 11, including rapid reporting expectations for actively exploited vulnerabilities. BleepingComputer
Recommended Actions
- Patch Magento/Adobe Commerce immediately; conduct full StyleSmuggler compromise hunting.
- Upgrade N-central to
2026.3.1.14or later and audit all management actions. - Deploy Microsoft September updates, prioritizing KEV-listed Windows vulnerabilities.
- Identify and restrict Windows NFS exposure; patch
CVE-2026-69595. - Apply SAP Patch Day updates and review internet-facing SAP components.
- Patch Roundcube, strongSwan, Red Hat Directory Server and IBM App Connect Enterprise where deployed.
- Hunt for ClearFake payloads, unauthorized NetSupport Manager installations and browser-based ClickFix activity.
- Continue remediation of previously reported items: MikroTik RouterOS, SharePoint, Citrix NetScaler, PaperCut, Chromium V8, SonicWall SMA1000 and Langflow.