CISA and BOD 26-04 require Federal Civilian Executive Branch agencies to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets. All organizations should apply available patches, adopt risk-based vulnerability management, and check for prior compromise before patching. Vulnerabilities can be nominated for addition to the KEV Catalog via CISA's KEV Nomination Form if they meet criteria of a CVE ID, evidence of exploitation, and clear mitigation guidance.
Quick answers
What is CVE-2026-85880?
CISA and BOD 26-04 require Federal Civilian Executive Branch agencies to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets. All organizations should apply available patches, adopt risk-based vulnerability management, and check for prior compromise before patching. Vulnerabilities can be nominated for addition to the KEV Catalog via CISA's KEV Nomination Form if they meet criteria of a CVE ID, evidence of exploitation, and clear mitigation guidance.
How severe is CVE-2026-85880?
high
Is CVE-2026-85880 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-85880 be mitigated?
CISA and BOD 26-04 require Federal Civilian Executive Branch agencies to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets. All organizations should apply available patches, adopt risk-based vulnerability management, and check for prior compromise before patching. Vulnerabilities can be nominated for addition to the KEV Catalog via CISA's KEV Nomination Form if they meet criteria of a CVE ID, evidence of exploitation, and clear mitigation guidance.
CVSS
—
Vendor
Adobe
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Adobe Commerce, Magento, Microsoft Windows, N-able N-central
Mitigation
CISA and BOD 26-04 require Federal Civilian Executive Branch agencies to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets. All organizations should apply available patches, adopt risk-based vulnerability management, and check for prior compromise before patching. Vulnerabilities can be nominated for addition to the KEV Catalog via CISA's KEV Nomination Form if they meet criteria of a CVE ID, evidence of exploitation, and clear mitigation guidance.
A Chinese threat actor tracked as UTA0565 has been observed exploiting a chain of three zero-day vulnerabilities - two in Google Chrome and one in Microsoft Windows - to deploy CLEANGULP malware. The attacks, detected in early September 2026, targeted users visiting fake websites and leveraged the exploit chain to achieve remote code execution and malware deployment. Google and Microsoft are expected to release security updates to address the vulnerabilities CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880.
The Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. The additions include CVE-2026-75650 affecting Adobe Commerce and Magento, CVE-2026-81963 and CVE-2026-85880 affecting Microsoft Windows, and CVE-2026-86218 affecting N-able N-central. CISA's Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of these KEV Catalog vulnerabilities on publicly exposed assets.