WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
CISA added WSO2 path traversal CVE-2026-5430 and Adobe Commerce authorization flaw CVE-2026-71362 to its KEV catalog amid active exploitation.
CISA added CVE-2026-5430 (CVSS 9.8), a path traversal in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway enabling unrestricted file upload and RCE, and CVE-2026-71362 (CVSS 9.1), an incorrect authorization flaw in Adobe Commerce and Magento allowing account takeover without user interaction. watchTowr observed in-the-wild exploitation of the WSO2 flaw on honeypots since September 13, 2026, and Sansec blocked exploitation attempts against the Adobe flaw in August 2026. FCEB agencies must remediate both vulnerabilities by September 27, 2026.
- CVE-2026-5430 (CVSS 9.8): WSO2 path traversal to unrestricted file upload and RCE
- CVE-2026-71362 (CVSS 9.1): Adobe Commerce session switching grants access to victim accounts
- watchTowr saw WSO2 exploitation since September 13; Sansec blocked Adobe attempts
- FCEB agencies must patch both vulnerabilities by September 27, 2026
Vulnerabilities mentionedAll →
- CVE-2026-543010.0<1%Unauthenticated JWT Algorithm Bypass in WSO2 API Manager and Gatewayspublished · wso2 api manager KEV PoC
Full article282 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 25, 2026Vulnerability / Web Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerabilities are listed below -
- CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remote code execution.
- CVE-2026-71362 (CVSS score: 9.1) - An incorrect authorization vulnerability in Adobe Commerce and Magento that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026.
As for CVE-2026-71362, Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw.
"The vulnerability lets attackers switch a customer session to another customer account," the Dutch e-commerce security company said. "This gives them access to the victim's account and private customer data."
Previdian's telemetry indicates that a lone IP address from Australia attempted to exploit the flaw targeting its honeypot sensors on September 10, 2026. Adobe has yet to update its advisory to confirm exploitation status.
Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.