VMTech
Discuss a project →

CISA adds exploited WSO2 and Adobe Commerce flaws to KEV

CISA adds exploited WSO2 and Adobe Commerce flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities affecting WSO2 products and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation. The entries are CVE-2026-5430, with a CVSS score of 9.8, and CVE-2026-71362, rated 9.1.

CVE-2026-5430 affects WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway. The path traversal vulnerability could permit unrestricted file upload and lead to remote code execution. CVE-2026-71362 is an incorrect authorization vulnerability in Adobe Commerce and Magento that could allow elevated access to sensitive resources without user interaction.

Evidence of exploitation emerged before KEV inclusion

watchTowr said it had observed in-the-wild exploitation attempts targeting its honeypots for the WSO2 issue since at least September 13, 2026. The KEV listing followed a little more than a week after that observation, underscoring that exposed API-management infrastructure is already being probed.

For the Adobe Commerce and Magento vulnerability, Sansec said in August 2026 that it had detected and blocked exploitation attempts. The Dutch e-commerce security company said the flaw allows an attacker to switch a customer session to another customer account, providing access to the victim’s account and private customer data.

Previdian telemetry also recorded a single IP address from Australia attempting to exploit CVE-2026-71362 against its honeypot sensors on September 10, 2026. Adobe had not updated its advisory to confirm the exploitation status at the time of the reporting.

Why the KEV entries matter

CISA’s KEV catalog tracks vulnerabilities with evidence of exploitation and is used to direct remediation priorities across U.S. federal civilian agencies. The latest additions build on CISA’s catalog of six exploited vulnerabilities by showing that actively exploited vulnerabilities continue to span both internet-facing application platforms and e-commerce environments.

For WSO2 deployments, the combination of path traversal, unrestricted file upload and potential remote code execution makes timely remediation especially important. For Adobe Commerce and Magento operators, the reported session-switching behavior highlights the risk to customer accounts and private data where the affected authorization control is exposed.

Required action for affected organizations

Federal Civilian Executive Branch agencies have been advised to apply fixes for both vulnerabilities by September 27, 2026. Other organizations running the affected WSO2 or Adobe platforms can use the same urgency: identify exposed instances, deploy the applicable vendor remediation, and review relevant logs for suspicious uploads, unexpected code execution, or anomalous customer-session activity.

The immediate business implication is to treat these fixes as active-incident prevention work, prioritizing internet-facing WSO2 and e-commerce systems before routine maintenance windows delay remediation.

#cybersecurity#vulnerability#appsecurity#ecommerce
Open analytics
On the site 1 views
min read 3 25.09.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

CISA adds exploited WSO2 and Adobe Commerce flaws to KEV

Open the post on Instagram ↗