Between September 7 and 9, 2026, German cybersecurity authorities disclosed multiple critical and high-severity vulnerabilities in widely-used software including N-central, Adobe Commerce, MongoDB, Google Chrome, and Langflow OSS. The vulnerabilities pose significant risks to enterprises and users.
A maximum-severity zero-day vulnerability called StyleSmuggler affecting Magento and Adobe Commerce was actively exploited starting September 4, 2026, to deploy Linux backdoors. Adobe released emergency patches (CVE-2026-75650) on September 8 after a three-day window of exposure.
Between 2026-09-07 and 2026-09-09, six critical and high-severity vulnerabilities were posted in German via a neonotu.com infosec feed, affecting Adobe Commerce (CVSS 10.0 remote code execution), Ivanti Neurons, Fortinet FortiSandbox, Microsoft Windows and Apps, and Adobe Magento, originating from NIST NVD and German BSI/CERT-Bund advisories.
Google patched CVE-2026-85046, a V8 type confusion vulnerability in Chrome that has been actively exploited in the wild and affects 3 billion users. This is the sixth actively exploited Chrome zero-day patched in 2026, with the U.S. federal deadline for patching set for September 18.
Between 2026-09-07 and 2026-09-09, Germany's CERT-Bund (BSI) disclosed multiple high and critical severity vulnerabilities affecting MikroTik RouterOS, rclone, Froxlor, strongSwan, Microsoft Office, and libxml2. Vulnerabilities ranged from critical remote code execution in MikroTik to high-severity issues in encryption and office software.
Adobe disclosed CVE-2026-75650 on September 8, 2026, a critical template-engine vulnerability (CVSS 10) in Adobe Commerce and Magento allowing unauthenticated remote code execution. The flaw is being actively exploited in the wild, requiring immediate patching across affected systems.
Between September 24-25, 2026, the Cybersecurity and Infrastructure Security Agency added five actively exploited software vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Adobe Commerce/Magento, MikroTik RouterOS, Microsoft SharePoint, and WordPress Core. The vulnerabilities range from authorization bypass to remote code execution.
CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither flaw is known to be used in ransomware campaigns.