CISA KEV adds exploited WSO2, Adobe, SharePoint, and MikroTik flaws
CISA ordered federal fixes for actively exploited WSO2, Adobe Commerce, SharePoint, and MikroTik flaws by September 27 or 28, 2026.
On September 24, 2026, CISA added actively exploited WSO2 CVE-2026-5430 and, according to The Hacker News, Security Affairs, and BleepingComputer, Adobe Commerce CVE-2026-71362 to its Known Exploited Vulnerabilities catalog, ordering federal civilian agencies to remediate both by September 27, 2026. Sources disagree on CVE-2026-5430: The Hacker News scores it CVSS 9.8 as path traversal in API Control Plane, API Manager, Traffic Manager, and Universal Gateway enabling unrestricted file upload and remote code execution, while Security Affairs and BleepingComputer score it CVSS 10.0 as failed JWT signature verification that can bypass authentication and seize accounts; Cyber Security News and GBHackers report both the path-traversal impact and CWE-347, and GBHackers cites a CVSS 10.0 scenario. BleepingComputer specifies API Manager 4.1.0 through 4.6.0 and related 4.5.0 and 4.6.0 components used by nearly 1,000 banking, government, telecom, and logistics customers; watchTowr observed exploitation on honeypots since September 13, which BleepingComputer narrows to limited forged-token attempts that day from one IP, and ransomware use is unconfirmed while BOD 26-04 requires forensic triage. CVE-2026-71362 (CVSS 9.1) is an incorrect-authorization flaw in Adobe Commerce and Magento that can switch sessions and take over accounts without user interaction; Security Affairs adds Commerce B2B and Magento Open Source through the July 2026 patches and access to private customer data, and Sansec said targeting began in August 2026. CISA also added SharePoint CVE-2026-65660 (CVSS 8.8; Server 2016, 2019, and Subscription Edition), which Microsoft revised from spoofing to remote code execution with reliable evidence of attacks as of September 25, 2026, and MikroTik RouterOS SSH-bypass CVE-2026-67279 (CVSS 6.9), both due September 28; CERT Polska dates MikroTik exploitation to at least September 2, and The Hacker News says the MikroTrick chain with already-listed CVE-2026-86060 can give passwordless administrative control of exposed RouterOS 7.x devices, while Security Affairs cites BOD 22-01 for that deadline.
- CISA added WSO2 CVE-2026-5430 and Adobe Commerce CVE-2026-71362 to the KEV catalog on September 24, 2026; FCEB agencies must remediate both by September 27, 2026.
- Sources disagree on CVE-2026-5430: The Hacker News scores it CVSS 9.8 as path traversal to unrestricted file upload and RCE, while Security Affairs and BleepingComputer score it CVSS 10.0 as a JWT signature-verification failure; Cyber…
- Affected WSO2 products include API Control Plane, API Manager 4.1.0 through 4.6.0, Traffic Manager, and Universal Gateway, used by nearly 1,000 customers; watchTowr saw activity since September 13, which BleepingComputer narrows to limited…
Coverage timelineoldest first · each row is one article
- · 2d agoWSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The Hacker News· 80
CISA added WSO2 path traversal CVE-2026-5430 and Adobe Commerce authorization flaw CVE-2026-71362 to its KEV catalog amid active exploitation.
- · 1d agoU.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
Security Affairs· 82
CISA added exploited WSO2 and Adobe Commerce flaws to the KEV catalog, with federal fixes due September 27.
- · 1d agoCISA Warns of WSO2 Multiple Products Vulnerability Exploited in Attacks
Cyber Security News· 82
Vulnerabilities in this storyAll →
- CVE-2026-543010.0<1%Unauthenticated JWT Algorithm Bypass in WSO2 API Manager and Gatewayspublished · wso2 api manager KEV PoC