U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
CISA added exploited WSO2 and Adobe Commerce flaws to the KEV catalog, with federal fixes due September 27.
CISA added CVE-2026-5430 and CVE-2026-71362 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate them by September 27, 2026. CVE-2026-5430, scored CVSS 10.0, affects multiple WSO2 products; the report describes failed JWT signature verification that can let attackers bypass authentication and take over accounts. CVE-2026-71362, scored CVSS 9.1, is an incorrect-authorization flaw in Adobe Commerce, Commerce B2B, and Magento Open Source through the July 2026 patches, allowing unauthenticated session switching and access to private customer data. Sansec said attackers began targeting the Adobe flaw in August 2026, shortly after disclosure.
- CVE-2026-5430 is a CVSS 10.0 WSO2 flaw described as a JWT authentication bypass.
- CVE-2026-71362, CVSS 9.1, lets attackers hijack Adobe Commerce customer sessions.
- Sansec observed exploitation attempts against the Adobe bug in August 2026.
- Federal agencies must fix both KEV entries by September 27, 2026.
Vulnerabilities mentionedAll →
- CVE-2026-543010.0<1%Unauthenticated JWT Algorithm Bypass in WSO2 API Manager and Gatewayspublished · wso2 api manager KEV PoC
Full article403 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 25, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
- CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability
The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products caused by improper verification of JWT signatures, allowing an attacker to use an unsupported signing algorithm to gain unauthorized access and potentially take over accounts.
The second flaw added to the catalog, tracked as CVE-2026-71362 (CVSS score 9.1), is an incorrect authorization vulnerability in Adobe Commerce that can allow an unauthenticated attacker to escalate privileges and gain access to sensitive resources without user interaction. In August 2026, hackers began targeting CVE-2026-71362 shortly after its public disclosure. The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data.
Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory. The flaw affects Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches. Adobe released an isolated fix and urged users to patch.
“Adobe has released APSB26-92 as isolated patch files. The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9.1. Sansec Shield already blocks exploitation attempts.” reads the advisory published by Sansec. “Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data.”
Sansec pointed out that an attacker can exploit the flaw without an existing account, administrator privileges, or user interaction.
Adobe fixed how Magento handles customer identity in account sessions. The remaining flaws include stored cross-site scripting and authorization issues.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaws by September 27, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)