CISA Flags Four Actively Exploited Vulnerabilities, Including Windows and Adobe Commerce Flaws
The US Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited by attackers. The flaws affect Microsoft Windows (two separate vulnerabilities, including a heap-based buffer overflow and a link-following issue), Adobe Commerce and Magento (a template engine flaw), and N-able N-central (a static code injection vulnerability).
While the formal directive requiring rapid remediation applies only to US federal agencies, CISA is urging all organisations, including small and medium businesses, to treat KEV-listed vulnerabilities as high priority. These are not theoretical risks: they are flaws already being used in real attacks, which makes them far more dangerous than unexploited vulnerabilities of similar severity.
Australian businesses running Windows systems, Adobe Commerce or Magento e-commerce platforms, or N-able N-central for remote monitoring and management should check whether they are affected and apply vendor patches as soon as possible. Managed service providers in particular should note the N-able N-central issue, as it is widely used for remote IT management.