CISA Adds Critical Microsoft, Adobe Flaws to Known Exploited Vulnerabilities Catalog
AI-generated from multiple sources. Verify before acting on this reporting.
WASHINGTON — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities catalog on Wednesday, September 10, 2026, listing critical flaws in Microsoft Windows, N-able N-central, and Adobe software that are being actively exploited in the wild. The addition mandates immediate remediation for federal agencies under Binding Operational Directive (BOD) 22-01, which requires the government to patch known exploited vulnerabilities within specific deadlines.
The update targets a range of high-risk security gaps identified across major software platforms. Among the newly listed entries are vulnerabilities in Microsoft Windows operating systems and Adobe applications, both of which remain ubiquitous across federal infrastructure and private sector networks. Additionally, CISA included flaws in N-able N-central, a remote monitoring and management platform widely used by managed service providers to administer client networks. The agency stated that these specific weaknesses have been observed in active attack campaigns, posing an immediate threat to national security systems.
Under BOD 22-01, federal agencies must remediate vulnerabilities listed in the catalog within 14 days of publication. Failure to comply can result in increased oversight and potential restrictions on agency operations. The directive aims to reduce the government's attack surface by forcing rapid patching of software that cyber adversaries have already weaponized. By adding these specific flaws to the catalog, CISA is signaling that threat actors are currently leveraging these entry points to compromise systems.
The inclusion of N-able N-central vulnerabilities highlights a growing concern regarding supply chain risks and third-party management tools. Because N-central allows administrators to control multiple remote devices simultaneously, a single compromised instance can potentially grant attackers access to an entire network of client machines. Similarly, the widespread adoption of Microsoft Windows and Adobe products means that unpatched systems in these categories represent a massive potential target for ransomware groups and state-sponsored actors.
CISA officials emphasized that the catalog serves as a critical resource for both public and private sector defenders. While the directive legally binds federal agencies, the agency encourages all organizations to treat the listed vulnerabilities as urgent priorities regardless of their sector. The update reflects a broader trend of increasing sophistication in cyberattacks, where adversaries move quickly to exploit newly disclosed or previously unknown weaknesses before patches are widely deployed.
As federal agencies rush to meet the 14-day deadline, questions remain regarding the extent of existing compromises within networks that have not yet applied the necessary updates. Security experts warn that the window between vulnerability disclosure and widespread exploitation is shrinking, leaving organizations with less time to assess risk and implement defenses. The agency has not specified which threat actors are responsible for the current campaigns targeting these specific flaws, though ongoing monitoring suggests coordinated activity across multiple sectors.