The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog with newly listed flaws affecting Microsoft Windows, N-able N-central remote monitoring software, and Adobe Commerce and Magento — all confirmed as actively exploited in the wild.
According to reporting by Security Affairs, CVE-2026-75650 carries a maximum CVSS severity score of 10.0. The vulnerability involves improper neutralization of special elements in Adobe Commerce and Magento, a class of flaw that can allow attackers to inject malicious input and compromise affected systems. Microsoft Windows and N-able N-central vulnerabilities were also added to the catalog, though the available summary focuses on the Adobe flaw's critical rating. Readers are encouraged to consult CISA's KEV catalog directly for the complete list of affected CVEs and remediation deadlines.
What the KEV catalog means
CISA's KEV catalog is not merely an informational resource. Under Binding Operational Directive (BOD) 22-01, all U.S. federal civilian agencies are required to remediate listed vulnerabilities within specified deadlines. While private-sector organizations are not legally bound by the directive, CISA consistently urges all enterprises to treat KEV additions as a priority — the catalog is curated specifically because each listed vulnerability has confirmed evidence of active exploitation.
This distinction matters: a high CVSS score alone does not earn a place in the KEV catalog. The requirement is proof that threat actors are leveraging the flaw in real-world attacks.
Implications for defenders
The inclusion of software spanning enterprise e-commerce (Adobe Commerce/Magento), remote monitoring and management platforms (N-able N-central), and ubiquitous operating system infrastructure (Microsoft Windows) signals a diverse and ongoing exploitation landscape. Attackers are not limiting themselves to a single attack surface — they are targeting the full stack of tools that organisations depend on for daily operations.
N-able N-central, widely used by managed service providers (MSPs), is a particularly high-value target. Compromising an MSP's monitoring tool can grant attackers lateral access across dozens or hundreds of downstream client environments, a pattern observed repeatedly in supply-chain and MSP-targeted intrusions in recent years.
For IT and security teams, the operational takeaway is straightforward: check whether your environment runs any of the affected products, prioritise patching against the listed CVEs, and assume that proof-of-concept or weaponised exploit code is likely already circulating among threat actors. Waiting for "more information" is a luxury that the KEV catalog is specifically designed to eliminate.
A broader signal
CISA's ongoing cadence of KEV updates underscores a persistent challenge facing defenders worldwide. Vulnerability disclosure is accelerating, but organisational patching cycles frequently lag behind the speed at which adversaries operationalise new exploits. Every addition to the catalog is a reminder that the window between public disclosure and active exploitation has effectively closed for high-impact flaws.
Organisations outside the United States — including those in the Asia-Pacific region operating under different regulatory frameworks — should still track KEV additions closely. The catalog serves as one of the most reliable indicators of which vulnerabilities are being weaponised right now, regardless of jurisdiction.
美國網絡安全及基礎設施安全局(CISA)已擴展其「已知遭利用漏洞」(KEV)目錄,新增收錄影響微軟Windows、N-able N-central遠程監控軟件,以及Adobe Commerce及Magento平台的漏洞,所有漏洞均證實在野外 actively exploited。
據Security Affairs報道,CVE-2026-75650獲最高CVSS嚴重評分10.0。該漏洞涉及Adobe Commerce及Magento對特殊元素的未妥善處理,此類漏洞可容許攻擊者注入惡意輸入並入侵受影響系統。微軟Windows及N-able N-central漏洞亦已列入目錄,惟現有摘要重點聚焦於Adobe漏洞的關鍵評級。讀者可直接查閱CISA的KEV目錄,以獲取受影響CVE的完整清單及修補期限。
KEV目錄的意義
CISA的KEV目錄不僅是資訊資源。根據具有約束力的操作指令(BOD)22-01,所有美國聯邦民事機構須在指定期限內修補目錄所列漏洞。雖然私營機構不受該指令法律約束,CISA持續敦促所有企業將KEV新增項目列為優先處理事項——該目錄經專門編纂,因每項列明漏洞均有確鑿證據顯示 actively exploited。
此點至關重要:僅憑高CVSS評分並不足以進入KEV目錄。入選要求是威脅行為者在實際攻擊中利用該漏洞的確鑿證據。
對防禦者的啟示
此次收錄的軟件涵蓋企業電子商務(Adobe Commerce/Magento)、遠程監控及管理平台(N-able N-central),以及廣泛使用的作業系統基礎設施(微軟Windows),顯示攻擊面多元且持續擴展。攻擊者並未局限於單一攻擊途徑,而是針對機構日常運作所依賴的完整工具鏈進行攻擊。
尤其值得注意的是,N-able N-central廣受管理服務供應商(MSP)採用,屬高價值目標。入侵MSP的監控工具可使攻擊者橫向滲透數十甚至數百個下游客戶環境,此模式在近年供應鏈及針對MSP的入侵事件中屢見不鮮。
對資訊科技及安全團隊而言,實務要點明確:檢查自身環境是否運行受影響產品,優先修補所列CVE漏洞,並假設概念驗證或武器化漏洞利用代碼很可能已在威脅行為者間流傳。等待「更多資訊」是KEV目錄設計上旨在消除的奢侈行為。
更廣泛的信號
CISA持續更新KEV目錄的節奏,突顯全球防禦者面臨的長期挑戰。漏洞揭露速度不斷加快,但機構修補週期往往落後於對手將新漏洞實戰化的速度。目錄中每一次新增,都提醒我們對於高影響力漏洞,公開揭露至 actively exploited 的窗口實質上已關閉。
美國以外的機構——包括在不同監管框架下運作的亞太區企業——仍應密切追蹤KEV新增項目。該目錄是判斷當前哪些漏洞正被武器化最可靠的指標之一,無論司法管轄區為何。
