Patch Analysis & Exploitation Timeline: Four CVEs, Two Confirmed Zero Days, CISA's September 8, 2026 KEV Additions
An analysis of four vulnerabilities added to the CISA Known Exploited Vulnerabilities catalog on September 8, 2026, covering public disclosure, patch availability, KEV inclusion, remediation deadlines, vulnerability classes, and patch prioritization considerations.
Dataset Summary
| Field | Value | Interpretation |
|---|---|---|
| Reporting Period | September 4–8, 2026 | Covers the earliest confirmed exploitation date established in public reporting for this cohort through the September 8 CISA KEV additions. |
| Data Sources | CISA KEV, official vendor/CNA records, and public exploitation research used only where a first-observed exploitation date or attribution question is documented. | KEV addition is treated as a formal exploitation signal, not as a proxy for the first day attackers exploited a vulnerability. |
| Total CVEs Analyzed | Four | CVE-2026-75650, CVE-2026-81963, CVE-2026-85880, and CVE-2026-86218. |
| Average Vendor-Publication-to-Patch Gap | 0 calendar days | All four vendors/CNAs made a public fix available on the same calendar date as the public bulletin or CVE publication used in this dataset. This does not mean exploitation started that day. |
| Average Patch-to-KEV Gap | 0.75 calendar days | KEV inclusion followed public fix availability within two days across the cohort. This is a formal confirmation metric, not a first-exploitation metric. |
| Median Patch-to-KEV Gap | 0.5 calendar days | Two Microsoft CVEs were added to KEV on the patch date; Adobe followed one day later and N-able two days later. |
| Confirmed Pre-Patch Exploitation | CVE-2026-75650 — 3 days | Independent research documents first confirmed StyleSmuggler exploitation on September 4; Adobe published APSB26-146 and the hotfix on September 7. |
| Additional Pre-Patch Compromise Signal | CVE-2026-86218 — September 4 customer compromise before September 6 HF4, but CVE-specific attribution is unresolved | Security researchers began investigating a compromised fully patched N-central environment on September 4. CVE-2026-86218 was later described as exploited in the wild, but the available evidence could not definitively identify which exploit caused that September 4 intrusion and the release notes separately state that production exploitation was unconfirmed. |
| Shortest / Longest Patch-to-KEV Gap | 0 days / 2 days | Shortest: CVE-2026-81963 and CVE-2026-85880. Longest: CVE-2026-86218. |
Sourcing and Methodology Note
This analysis covers CVE-2026-75650, CVE-2026-81963, CVE-2026-85880, and CVE-2026-86218, all recorded as September 8, 2026 additions to the CISA Known Exploited Vulnerabilities catalog. Vendor publication and patch dates are taken from Adobe APSB26-146, the corresponding Microsoft CVE-2026-81963 and Microsoft CVE-2026-85880 records, and N-able's 2026.3 HF4 release notes.
First-observed exploitation is handled separately from vendor publication. For CVE-2026-75650, independent research provides a dated first-confirmed exploitation event on September 4, 2026. For CVE-2026-86218, the chronology is less certain: security researchers began investigating a compromised fully patched N-central customer environment on September 4, while a public active incident notice describes the newly identified vulnerability as exploited in the wild. However, the available evidence indicates that rotated logs prevent definitive attribution of the September 4 compromise to CVE-2026-86218, and the HF4 release notes say production exploitation had not been confirmed at the time of that release.
Accordingly, this post does not use KEV addition as the literal first-exploitation date. The standardized patch-to-KEV metric is retained because it is available for all four CVEs, while an exploitation-to-patch gap is calculated only where a dated first-exploitation event can be attributed to the CVE with sufficient confidence. Missing or disputed dates are marked unavailable rather than estimated.
Introduction
The September 8, 2026 KEV cohort examined here spans four vulnerabilities across Adobe Commerce and Magento Open Source, Microsoft Windows, and N-able N-central. The weaknesses include template-engine injection, link-following and access-control errors, a heap-based buffer overflow, and static code injection leading to pre-authentication remote code execution.
At first glance, the vendor-publication-to-patch timeline is extremely compressed: a public fix was available on the same calendar date as the public bulletin or CVE record used for all four entries, and KEV inclusion followed zero to two days later. That view is accurate as a publication metric, but it misses the most important exploitation detail in the batch.
For CVE-2026-75650, independent research documents confirmed exploitation beginning September 4, three days before Adobe's September 7 hotfix. The same investigation documents a Rust-based Linux backdoor on compromised stores and, by September 7, activity from a separate attacker deploying a PHP web shell. CVE-2026-86218 also carries a pre-patch incident signal: security researchers began investigating a compromised N-central customer environment on September 4, two days before HF4 became public, although the specific CVE used in that intrusion cannot be proven from the remaining logs. The distinction between vendor disclosure date and first observed exploitation is therefore central to interpreting this dataset correctly.
Background and Context
CVE-2026-75650 is a critical unauthenticated vulnerability affecting Adobe Commerce and Magento Open Source that can result in arbitrary code execution. Adobe published APSB26-146 on September 7 with a CVSS v3.1 base score of 10.0 and confirmed exploitation in the wild. Independent incident chronology places first confirmed exploitation on September 4, before the vendor hotfix became available.
The two Microsoft entries are local elevation-of-privilege issues. CVE-2026-81963 involves improper link resolution and access control in the Windows Update Stack, while CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC). Microsoft's public CVE records assign both a CVSS v3.1 base score of 7.8. The public sources reviewed establish exploitation strongly enough for CISA KEV inclusion, but they do not establish a precise first-exploitation date for either CVE.
CVE-2026-86218 affects N-able N-central versions before 2026.3.1.14 and can permit pre-authentication remote code execution. The CNA record assigns CVSS v4.0 10.0, while NVD also publishes a CVSS v3.1 9.8 score. A public incident communication describes the issue as a critical zero-day that had been observed exploited in the wild, but the HF4 release notes state that production exploitation had not been confirmed at that time. Independent security research documents a September 4 compromise of a fully patched N-central customer environment but notes that the specific vulnerability used cannot be determined because relevant appliance logs had rotated.
Gap Calculation Methodology
Four timeline values are tracked where available: vendor/CNA public date, first observed exploitation date, public patch or hotfix availability date, and CISA KEV date added. The calendar-day calculations are:
Vendor-Publication-to-Patch Gap = Patch Availability Date − Vendor/CNA Public Date
Exploitation-to-Patch Lead = Patch Availability Date − First Confirmed Exploitation Date
Patch-to-KEV Gap = CISA KEV Date Added − Patch Availability Date
Remediation Window = CISA Due Date − CISA KEV Date Added
A positive exploitation-to-patch value means exploitation was observed before the public fix. That metric is calculated only when the first-exploitation event can be tied to the CVE. It is therefore 3 days for CVE-2026-75650, unavailable for both Microsoft CVEs, and not assigned to CVE-2026-86218 because the September 4 N-central compromise cannot be definitively attributed to that specific CVE.
For the standardized publication metric, September 8 is used as the Microsoft public and patch date, September 7 for Adobe's bulletin and hotfix, and September 6 for N-able's HF4 public availability. All calculations use calendar days; same-day values do not imply a specific intraday sequence.
Patch Timeline & Exploitation Gap Analysis
The standardized vendor-publication-to-patch gap is zero calendar days for all four CVEs, and the patch-to-KEV gap ranges from zero to two days. On that basis, the average patch-to-KEV gap is 0.75 days and the median is 0.5 days.
| Patch-to-KEV Gap | Number of CVEs | Share of Dataset |
|---|---|---|
| 0 days | 2 | 50% |
| 1 day | 1 | 25% |
| 2 days | 1 | 25% |
The exploitation chronology changes the interpretation of those figures. CVE-2026-75650 was already being exploited three calendar days before Adobe's hotfix, so its true defensive exposure window began before the vendor disclosure date used by the standardized publication metric. Independent research also documents post-compromise deployment of a Rust backdoor and later PHP web-shell activity on affected stores.
CVE-2026-86218 presents a second, but less cleanly attributable, pre-patch signal. Security researchers began investigating a compromised fully patched N-central production environment on September 4, while HF4 was published on September 6. A public incident notice called the new vulnerability exploited in the wild, but the retained logs could not establish whether CVE-2026-86218 itself was the exploit used in that September 4 intrusion. The article therefore does not convert that chronology into a numeric CVE-specific exploitation-to-patch gap.
Because precise first-exploitation dates are unavailable for the two Microsoft CVEs and disputed for the N-able case, a dataset-wide average or median exploitation-to-patch gap would be misleading and is not calculated. The 0.75-day patch-to-KEV average remains useful only as a measure of how quickly formal KEV inclusion followed public fix availability.
CVE Timeline Data
| CVE ID | Vendor / Product | Vendor/CNA Public Date | First Observed / Reported Exploitation | Patch Available | KEV Added | Days: Public Date → Patch | Days: Exploitation → Patch | Days: Patch → KEV | CISA Due Date |
|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-75650 | Adobe Commerce / Magento Open Source | September 7, 2026 | September 4, 2026 — first confirmed StyleSmuggler exploitation | September 7, 2026 | September 8, 2026 | 0 | 3 days pre-patch | 1 | September 11, 2026 |
| CVE-2026-81963 | Microsoft Windows Update Stack | September 8, 2026 | Exact first-exploitation date unavailable in reviewed public sources | September 8, 2026 | September 8, 2026 | 0 | Unavailable | 0 | September 22, 2026 |
| CVE-2026-85880 | Microsoft Windows ALPC | September 8, 2026 | Exact first-exploitation date unavailable in reviewed public sources | September 8, 2026 | September 8, 2026 | 0 | Unavailable | 0 | September 22, 2026 |
| CVE-2026-86218 | N-able N-central | September 6, 2026 | September 4 customer compromise investigated by security researchers; specific CVE attribution unresolved. The new vulnerability was separately described as exploited in the wild. | September 6, 2026 | September 8, 2026 | 0 | Not calculated — attribution unresolved | 2 | September 11, 2026 |
Statistical Distribution and Outliers
The patch-to-KEV distribution is tightly clustered: two CVEs have a zero-day gap, one has a one-day gap, and one has a two-day gap. That produces an average of 0.75 days and a median of 0.5 days. With only four entries, the sample is too small to support broader conclusions about vendor performance or industry-wide patch timing.
The exploitation-to-patch distribution cannot be summarized with a meaningful cohort average because only one CVE has a public, dated, and sufficiently attributable first-exploitation event. That outlier is also the most important case in the dataset: CVE-2026-75650 has a confirmed three-day zero-day window between first observed exploitation on September 4 and Adobe's hotfix on September 7.
CVE-2026-86218 is analytically important for a different reason. The September 4 compromise predates HF4 by two days, but the specific exploit used cannot be recovered from the available logs. N-able's public communications also contain a material discrepancy: the active incident notice and later customer blog describe exploitation in the wild, while the HF4 release notes state that production exploitation had not been confirmed at that point. The uncertainty is retained rather than resolved by assumption.
CISA remediation deadlines split the cohort into two tracks: Adobe and N-able have September 11 due dates, while the two Microsoft entries have September 22 due dates. Measured from the September 8 KEV addition date, those correspond to three-day and 14-day remediation windows.
Vulnerability Class Breakdown
| CVE | Product | Vulnerability Class | CWE | Published Severity |
|---|---|---|---|---|
| CVE-2026-75650 | Adobe Commerce / Magento Open Source | Improper Neutralization in a Template Engine | CWE-1336 | Critical — CVSS v3.1 10.0 |
| CVE-2026-81963 | Microsoft Windows Update Stack | Link Following / Improper Access Control | CWE-59, CWE-284 | High — CVSS v3.1 7.8 |
| CVE-2026-85880 | Microsoft Windows ALPC | Heap-Based Buffer Overflow / Use of Uninitialized Resource | CWE-122, CWE-908 | High — CVSS v3.1 7.8 |
| CVE-2026-86218 | N-able N-central | Static Code Injection | CWE-96 | Critical — N-able CNA CVSS v4.0 10.0; NVD CVSS v3.1 9.8 |
The N-able scoring detail requires version context. The CVE record supplied by N-able as the CNA contains a CVSS v4.0 base score of 10.0. NVD separately publishes a CVSS v3.1 base score of 9.8. Both characterize the issue as Critical, but the numeric values should not be presented as though they were produced under the same scoring standard.
The sample contains too few repeated examples of any one vulnerability class to support a meaningful class-level timing comparison.
Notable Case Highlights
CVE-2026-75650: Adobe Commerce and Magento Open Source
Adobe published APSB26-146 on September 7, 2026 for CVE-2026-75650, a critical CWE-1336 vulnerability with a CVSS v3.1 base score of 10.0. Adobe states that exploitation requires no authentication and can result in arbitrary code execution, and it confirms exploitation in the wild. Independent chronology moves the exploitation start three days earlier than the bulletin: the first confirmed StyleSmuggler exploitation is dated September 4 at 22:20 UTC, with the Adobe hotfix following on September 7. Independent research later documented a Rust-based Linux backdoor and a separate attacker dropping a PHP web shell on compromised stores. CISA added the vulnerability to KEV on September 8 with a September 11 remediation deadline.
CVE-2026-81963 and CVE-2026-85880: Microsoft Windows
Both Microsoft vulnerabilities were public on September 8 and were added to KEV the same day. CVE-2026-81963 is a Windows Update Stack elevation-of-privilege vulnerability involving improper link resolution and access control. CVE-2026-85880 is a Windows ALPC elevation-of-privilege vulnerability caused by a heap-based buffer overflow and use of an uninitialized resource. Microsoft's official CVE records identify both as CVSS v3.1 7.8 and link to the corresponding security updates. The reviewed public sources do not establish a precise first-exploitation date for either CVE, so no exploitation-to-patch interval is assigned.
CVE-2026-86218: N-able N-central
CVE-2026-86218 affects N-central versions before 2026.3.1.14 and can allow pre-authentication remote code execution through static code injection. The CNA record scores it CVSS v4.0 10.0, while NVD supplies a separate CVSS v3.1 9.8 assessment. N-able published HF4 on September 6 and CISA added the CVE to KEV on September 8.
The exploitation chronology should be presented with its evidentiary limits intact. Security researchers began investigating a compromised fully patched N-central production environment on September 4 and later reproduced an exploit chain for the separately disclosed CVE-2026-86206/CVE-2026-86207 pair. A September 6 active incident notice then described a third, unrelated vulnerability, CVE-2026-86218, as observed exploited in the wild and called it a zero-day. At the same time, the HF4 release notes state that production exploitation was not confirmed, and the available evidence cannot determine from the rotated logs whether CVE-2026-86218 was the exploit used in the September 4 compromise. The blog therefore treats the case as a strong pre-patch exploitation signal with unresolved CVE-specific attribution, not as a confirmed two-day exploitation-to-patch interval.
Historical Trend Comparison
A historical trend comparison is not presented because no prior reporting period using the same separation between vendor-publication dates, first-observed exploitation dates, patch dates, and KEV dates was supplied for this analysis. Comparing this cohort with a differently constructed dataset could create a misleading widening or narrowing trend.
MITRE ATT&CK Mapping
A dataset-wide technique-level ATT&CK mapping is not assigned in this post. The reviewed public sources establish vulnerability classes, affected products, and exploitation status, but they do not provide a sufficiently consistent set of observed attacker behaviors across all four cases to support a common technique mapping without inference.
Risk Context for Organizations
The central risk lesson from this cohort is that a zero-day publication-to-patch value does not imply a zero-day exposure window. CVE-2026-75650 was exploited for three days before Adobe's hotfix, and compromised stores were observed receiving persistent malware. Internet-facing Adobe Commerce and Magento environments that were exposed during that period require compromise assessment in addition to patch verification.
N-central presents a similar need for caution even though the exact September 4 exploit path remains unresolved. A production compromise occurred before HF4, the newly identified CVE was described as exploited in the wild, and successful exploits against customers were later reported. Organizations should therefore avoid using the absence of a definitive September 4 CVE attribution as evidence that pre-patch N-central exposure was benign.
The Microsoft entries have a different risk profile because they are local elevation-of-privilege vulnerabilities. Their inclusion in KEV indicates exploitation, but the public sources reviewed do not establish when exploitation began relative to patch availability. Prioritization should account for whether an attacker could already obtain local execution on affected systems.
Detection and Patch Prioritization Considerations
- Identify Adobe Commerce, Magento Open Source, affected Windows builds, and N-central servers in the asset inventory, then confirm exact versions and applied hotfixes against the vendor records.
- For Adobe Commerce and Magento, do not stop at patch validation. Systems exposed from September 4 until the September 7 hotfix should be reviewed for signs documented in the StyleSmuggler investigation, including unexpected failed-payment reminder activity, suspicious PHP files in writable media paths, and the observed backdoor process or persistence artifacts.
- Apply Adobe's CVE-2026-75650 hotfix and complete any additional vendor-required post-fix steps. Treat internet-facing systems that were vulnerable during the zero-day window as candidates for compromise assessment.
- Upgrade on-premises N-central to 2026.3 HF4 / build 2026.3.1.14 or a later fixed release. Review available detection guidance, including unexpected user accounts,
.invalidemail patterns, API manipulation, and other activity associated with the September incidents. - Deploy the applicable September 8 Microsoft security updates for CVE-2026-81963 and CVE-2026-85880 on affected Windows versions and validate the resulting build levels.
- Correlate the Windows local elevation-of-privilege CVEs with evidence of preceding initial access or local code execution, because successful exploitation requires an attacker to already have a local execution path.
- Validate remediation after deployment rather than relying only on installer success, and document exceptions or compensating controls where immediate patching is not possible.
Key Takeaways
- Four vulnerabilities in this September 8, 2026 cohort were added to the CISA KEV catalog: one Adobe, two Microsoft, and one N-able vulnerability.
- The 0-day vendor-publication-to-patch figure is accurate for all four CVEs, but it does not represent the beginning of attacker activity.
- CVE-2026-75650 has a confirmed three-day zero-day window: first confirmed exploitation on September 4 and an Adobe hotfix on September 7.
- CVE-2026-86218 has a pre-patch compromise signal beginning September 4, but the specific CVE used in that intrusion cannot be proven from the retained logs. Public communications also contain conflicting statements about exploitation confirmation.
- The standardized patch-to-KEV gap remains narrow at 0–2 days, with a 0.75-day average and 0.5-day median, but it should be treated as a formal prioritization-signal metric rather than a first-exploitation metric.
- For CVE-2026-86218, the CNA score is CVSS v4.0 10.0, while NVD separately publishes CVSS v3.1 9.8; both are Critical but should not be conflated as the same scoring standard.
Conclusion
The September 8, 2026 KEV cohort demonstrates why vendor disclosure dates and first-observed exploitation dates must be tracked separately. A same-day bulletin-and-patch record can look like a zero-day disclosure-to-patch gap while still hiding a meaningful period of attacker activity before the fix became public.
CVE-2026-75650 is the clearest example: confirmed exploitation began on September 4, three days before Adobe's September 7 hotfix. CVE-2026-86218 adds a second warning signal because a fully patched N-central environment was compromised on September 4 and the newly identified vulnerability was subsequently described as exploited in the wild, even though the available evidence could not definitively attribute that intrusion to the CVE and the release notes used more cautious language.
For this dataset, the patch-to-KEV metric remains useful for measuring the speed of formal exploitation-based prioritization, but it should not be mistaken for the beginning of exploitation. Vulnerability management teams need both timelines: when a fix became public and, where evidence exists, when attackers were first observed using the flaw.
Constantly Fix Risks with Saner Patch Management
Saner Patch Management is a continuous, automated, and integrated patch management solution that helps organizations identify, prioritize, and remediate vulnerabilities actively exploited in the wild. It supports Windows, Linux, macOS, and more than 550 third-party applications, enabling timely deployment of security updates across enterprise environments.
The platform also provides safe patch testing environments, automated deployment workflows, compliance reporting, and patch rollback capabilities to minimize operational risk while ensuring critical vulnerabilities are addressed without delay.
Experience the fastest and most accurate patching software here.



