What to patch now — 14 September 2026
Source: CISA Known Exploited Vulnerabilities (KEV) catalog — the most recently added entries as of today. Every vulnerability below has been confirmed by CISA as actively exploited in the wild, meaning attackers are already using it, not just researching it. If you (or a supplier) run any of this software, treat it as urgent.
1. Adobe Commerce and Magento — a booby-trapped page template can run an attacker's code (CVE-2026-75650)
🛠️ Adobe Commerce and Magento Open Source · added 8 Sep 2026 · CISA fix-by date 11 Sep 2026 (3 days overdue)
What it is: Magento builds its store pages from "templates" — reusable layouts that get filled in with real content. "Improper neutralization of special elements" means the template engine doesn't properly filter out attacker-supplied instructions hidden inside content it processes, so a crafted piece of input can make the template engine execute the attacker's own code on the server, not just display text.
Who's affected: Any small e-shop or store owner running Adobe Commerce or the free Magento Open Source platform to sell online — a very common choice for independent retailers.
What to do: Apply Adobe's fix — the deadline has passed. If you or an agency manages your Magento store, ask them to confirm it's patched today; a store's checkout and customer data sit directly behind this.
2. Microsoft Windows — two bugs that hand an attacker who's already in your PC full control (CVE-2026-81963, CVE-2026-85880)
🛠️ Microsoft Windows · added 8 Sep 2026 · CISA fix-by date 22 Sep 2026
What it is: Both are "privilege escalation" bugs — they don't let anyone break into your computer from the outside, but if an attacker has already got a foothold (say, through a phishing email or malicious attachment) they can use either bug to jump from an ordinary user account to full SYSTEM-level control. One tricks a Windows update process into following a link it shouldn't; the other overflows a memory buffer in a core Windows messaging component.
Who's affected: Practically every business — anyone running Windows.
What to do: These land through the normal monthly Windows Update, so if automatic updates are on and you restart your PC regularly, you're likely already covered. Worth confirming with whoever manages your machines that this month's update has actually installed.
3. N-able N-central — a flaw in the software many IT providers use to manage your computers, no login required (CVE-2026-86218)
🛠️ N-able N-central · added 8 Sep 2026 · CISA fix-by date 11 Sep 2026 (3 days overdue)
What it is: N-central is "remote monitoring and management" (RMM) software — the tool an outsourced IT provider runs behind the scenes to keep an eye on and update its clients' computers, often for dozens of businesses at once. "Static code injection" here means an attacker with no login at all can plant and run their own code on the N-central server itself.
Who's affected: You may never have heard of N-central, but if your business outsources IT support, there's a real chance your provider uses it — and a single compromised RMM server can be a foothold into every client it manages.
What to do: Apply N-able's fix — the deadline has passed. Ask your IT provider directly whether they run N-central and whether it's patched; this is exactly the kind of behind-the-scenes tool that's worth a five-minute phone call to check.
4. Citrix NetScaler — an attacker can walk past the login on your remote-access gateway (CVE-2026-19490)
🛠️ Citrix NetScaler ADC and Gateway · added 9 Sep 2026 · CISA fix-by date 12 Sep 2026 (2 days overdue)
What it is: NetScaler devices are what many businesses use to give staff secure remote access — VPN, SSL VPN or remote-desktop-style connections into the office network. "Authentication bypass using an alternate path" means that when the device is set up for this kind of remote access, an attacker with no valid login can find a side door around the authentication check entirely.
Who's affected: Businesses (or their IT provider) using a Citrix NetScaler appliance so staff can log in remotely.
What to do: Apply Citrix's fix — the deadline has passed. Ask your IT provider whether "NetScaler" is part of your remote-access setup; this class of device is a favourite target precisely because it's designed to be reachable from the public internet.
5. Fortinet firewalls and network gear — a crafted network packet can run an attacker's code (CVE-2025-25249)
🛠️ Fortinet FortiOS, FortiSwitchManager and FortiSASE · added 9 Sep 2026 · CISA fix-by date 12 Sep 2026 (2 days overdue)
What it is: A "heap-based buffer overflow" means the software can be sent more data than it expects to handle, spilling over into memory it shouldn't touch — and a carefully built network packet can turn that spill into the attacker's own commands running on the device.
Who's affected: Businesses using a Fortinet firewall, switch-management console or SASE (secure remote-access) service — common gear for small-office networks, often set up by a local IT provider.
What to do: Apply Fortinet's fix — the deadline has passed. Ask whoever set up your network whether you're on Fortinet kit and whether it's been updated; firewalls sit at the edge of your network by design, which is exactly where this matters most.
6. Chrome, Edge and other Chromium browsers — another bug that can run code from a malicious page (CVE-2026-87491)
🛠️ Google Chromium V8 (Chrome, Edge, Opera and other Chromium browsers) · added 9 Sep 2026 · CISA fix-by date 23 Sep 2026
What it is: A second browser-engine bug in as many weeks. "Out of bounds write" means the browser's JavaScript engine can be made to write data outside the memory it's supposed to use — and a crafted web page can turn that into the attacker's own code running inside the browser's sandbox, just from loading the page.
Who's affected: Practically every business — this is the same browser most staff use every day.
What to do: As with last week's browser bug, the fix installs automatically but only takes effect after a restart. Close and reopen your browser rather than leaving it running for days.
7. Cisco Secure Firewall Management Center — an unauthenticated attacker can take root on the underlying server (CVE-2026-20079)
🛠️ Cisco Secure Firewall Management Center (FMC) and Security Cloud Control · added 9 Sep 2026 · CISA fix-by date 12 Sep 2026 (2 days overdue)
What it is: FMC is the console used to manage Cisco firewalls centrally. "Authentication bypass using an alternate path" means an unauthenticated attacker can sidestep the login check and run their own scripts, ending up with root — full administrator-level — access to the machine running it.
Who's affected: Mostly larger networks and the IT providers who manage them, since FMC is a central management console rather than something a small office would run directly — but if a supplier manages your Cisco firewalls through it, their compromise can become yours.
What to do: Apply Cisco's fix — the deadline has passed. If a managed-service provider looks after your network, ask them directly whether Firewall Management Center is part of how they manage it.
8. MikroTik RouterOS — two bugs in a budget router brand used by small offices everywhere (CVE-2026-86060, CVE-2026-67277)
🛠️ MikroTik RouterOS · added 10 Sep 2026 · CISA fix-by date 13 Sep 2026 (1 day overdue)
What it is: MikroTik makes inexpensive, capable routers popular with small businesses, cafés and hotels for wired and Wi-Fi networking. One bug lets an attacker slip extra commands past the router's own safety checks to raise their access level; the other skips an authentication check on a built-in speed-test feature, letting an outsider crash the router or pull data out of its memory.
Who's affected: Any small business running MikroTik hardware for its office or guest network — chosen precisely because it's cheaper than the big-name brands, so it's common in exactly the kind of budget-conscious setup this platform serves.
What to do: Apply MikroTik's fix — the deadline has passed. Log into your router's admin panel (or ask whoever set it up) and check the RouterOS version; these are quick updates once you know to look.
9. ConnectWise ScreenConnect — a remote-support tool can be made to move files without your OK (CVE-2026-84869)
🛠️ ConnectWise ScreenConnect · added 11 Sep 2026 · CISA fix-by date 14 Sep 2026 (due today)
What it is: ScreenConnect is remote-support software — an IT provider uses it to connect to your computer over the internet to fix problems. "Improper privilege management and missing authorization" means that during an active support session, files can be transferred and run on your machine without the usual host confirmation or authorization check that's meant to keep that under your control.
Who's affected: Any business whose IT support or help desk connects to your computers using ScreenConnect — a very widely used tool, and one that's been abused in real ransomware attacks in the past precisely because it's a trusted, already-installed way onto a target's machine.
What to do: Apply ConnectWise's fix — the deadline is today. Ask your IT support provider whether they use ScreenConnect and whether it's current; you're trusting this software with hands-on access to your machines.
10. JFrog Artifactory — two more authentication flaws, three weeks running now (CVE-2026-42016, CVE-2026-42018)
🛠️ JFrog Artifactory · added 11 Sep 2026 · CISA fix-by date 25 Sep 2026
What it is: Artifactory stores and distributes a development team's own software builds. This is the third consecutive week this platform has appeared here, each time with a different problem. This time: one bug checks only that an access token is validly signed, not what it's actually allowed to do, letting a low-privilege token be used to gain higher privileges; the other can hand out an internal "anonymous access" token to an unauthenticated visitor even when anonymous access has been switched off.
Who's affected: Development teams — yours or a contractor's — running their own Artifactory instance rather than a hosted alternative.
What to do: If your development team or a contractor runs Artifactory, this is the third week running it's needed attention — worth checking it's actually being kept current rather than patched once and left. Confirm it isn't exposed to the open internet unnecessarily.
11. GitLab (self-hosted) — a hole in the commits API lets a stranger read files off your server (CVE-2026-85706)
🛠️ GitLab Community Edition and Enterprise Edition · added 11 Sep 2026 · CISA fix-by date 14 Sep 2026 (due today)
What it is: "Path traversal" means the software can be tricked into reading a file outside the folder it's supposed to be confined to, by feeding it a crafted file path. Here that flaw sits in GitLab's commits API and, combined with a missing authentication check, lets someone with no account at all read arbitrary files off the server.
Who's affected: Businesses that self-host GitLab to store their own source code, rather than using GitLab's own cloud service (gitlab.com) or an alternative like GitHub.
What to do: Apply GitLab's fix — the deadline is today. If your development team or a contractor self-hosts GitLab, confirm it's updated; a self-managed instance is your responsibility to patch, unlike a hosted SaaS product.
This is an awareness summary of public CISA KEV data, not professional security advice. CISA "fix-by" dates are US federal deadlines; for everyone else they're a strong urgency signal, not a legal obligation. Always confirm the affected versions and the fix against the vendor's own advisory.