Between September 7 and 9, 2026, German cybersecurity authorities disclosed multiple critical and high-severity vulnerabilities in widely-used software including N-central, Adobe Commerce, MongoDB, Google Chrome, and Langflow OSS. The vulnerabilities pose significant risks to enterprises and users.
Between 2026-09-07 and 2026-09-09, six critical and high-severity vulnerabilities were posted in German via a neonotu.com infosec feed, affecting Adobe Commerce (CVSS 10.0 remote code execution), Ivanti Neurons, Fortinet FortiSandbox, Microsoft Windows and Apps, and Adobe Magento, originating from NIST NVD and German BSI/CERT-Bund advisories.
CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither flaw is known to be used in ransomware campaigns.
A maximum-severity zero-day vulnerability called StyleSmuggler affecting Magento and Adobe Commerce was actively exploited starting September 4, 2026, to deploy Linux backdoors. Adobe released emergency patches (CVE-2026-75650) on September 8 after a three-day window of exposure.
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.
Between September 7 and 9, 2026, cybersecurity researchers reported multiple new vulnerabilities affecting Dell Secure Connect Gateway, D-Link routers, Microsoft Windows, and Fortinet FortiOS, with several rated as severe or high-severity. Active exploitation of Fortinet vulnerabilities was also noted.
Adobe Commerce faces a CRITICAL (CVSS 10) template engine flaw (CVE-2026-75650) allowing arbitrary code execution with no user interaction required. Update and monitor for patches.
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes).