News

CISA Adds Exploited WSO2 and Adobe Commerce Flaws to KEV as Attackers Hit Live Targets

CISA added critical WSO2 (CVSS 9.8) and Adobe Commerce (CVSS 9.1) flaws to its exploited list after attackers began probing them, giving federal agencies until 27 September to patch.

CISA Adds Exploited WSO2 and Adobe Commerce Flaws to KEV as Attackers Hit Live Targets

Attackers are already going after two critical flaws, one in the API gateways banks and governments use to route traffic and one in the Adobe Commerce stores behind a large slice of online retail. CISA has now added both to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.

Federal civilian agencies have until 27 September 2026 to apply the fixes, a window of barely two days.

The more severe bug, CVE-2026-5430 (CVSS 9.8), is a path traversal flaw in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. It can let an attacker upload files without restriction and run code on the server. WSO2's platform is used by nearly 1,000 customers across banking, government, telecommunications, and logistics.

Public technical detail on the WSO2 flaw is thin, but that has not slowed anyone down. Researchers at watchTowr saw exploitation attempts using forged JWTs against their honeypots since at least 13 September.

The second flaw, CVE-2026-71362 (CVSS 9.1), is an incorrect authorization bug in Adobe Commerce and Magento. It can let an attacker gain elevated access and switch a customer's session to another account without the victim doing anything, exposing private customer data.

Adobe patched it in its APSB26-92 advisory in August. Sansec detected and blocked exploitation attempts after that disclosure, and Previdian telemetry picked up a lone Australian IP address hitting its honeypots on 10 September. Adobe's own advisory may not yet reflect that the bug is being exploited, so store owners reading only the vendor page could underestimate the risk, as Security Affairs noted.

A KEV listing means exploitation is real, not that every WSO2 or Magento deployment has been breached. No ransomware group or named campaign has been tied to either flaw so far.

That can change quickly. The TeamCity flaw CISA flagged earlier followed the familiar path from honeypot probes to ransomware crews once exploit details spread.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free