CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
At a glance
- Severity
- CriticalCVSS 10.0
- Used in attacks
- Yes, 1 of 1 flaw named
- Flaws named
- CVE-2026-5430
- Vendors and products
- AdobeSharePoint
- Industries
- Government
- Reported by
- 1 outlet
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.
The agency also added CVE-2026-71362, another critical-severity flaw affecting Adobe Commerce, to the list of security issues being leveraged in attacks.
Hackers are also exploiting two additional vulnerabilities: a high-severity code injection flaw in Microsoft SharePoint tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS identified as CVE-2026-67279.
For the two critical issues added to the Known Exploited Vulnerabilities (KEV) catalog, federal agencies using the affected products have until Sunday, September 27, to apply the recommended updates or mitigations, or discontinue their use.
The CVE-2026-5430 flaw received a maximum severity score and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
In the original advisory on May 3, the vendor says that an attacker successfully exploiting the vulnerability could compromise administrative accounts and take full control.
The problem stems from the JWT authentication mechanism accepting tokens signed with an unsupported algorithm.
CISA has not shared any details about the attacks, but security firm watchTowr announced on September 15 announced that its honeypots captured exploitation attempts.
The researchers said they observed a limited number of attempts from one IP address on September 13 using forged JWT tokens against a WSO2 product. However, the attacker targeted the wrong product for CVE-2026-5430.
watchTowr reproduced the attack on the correct product, where a forged token could expose API endpoints and application credentials.
Yordan Ganchev, threat intelligence specialist at watchTowr, told BleepingComputer that WSO2 is not a niche target.
“Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics,” explained Ganchev.
“Organizations in these sectors can't afford to wait for exploitation to be formally confirmed.”
The second critical-severity bug added to the KEV is CVE-2026-71362, an incorrect authorization vulnerability in Adobe's Commerce and Magento e-commerce platforms.
Ecommerce security company Sansec observed CVE-2026-71362 being exploited in the wild, saying that threat actors require "no existing account, administrator privileges, or user interaction" to leverage it.
The deadline for federal agencies to mitigate both vulnerabilities is September 27, but CISA encourages all organizations to take action and prioritize addressing the security issues listed in the KEV.
For the Microsoft SharePoint and Mikrotik RouterOS flaws, CISA is giving agencies until Monday, September 28 to fix them.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Originally published by BleepingComputer. © BleepingComputer. Written by Bill Toulas.
Vulnerabilities referenced
- CVE-2026-543010.0Critical
WSO2 Multiple Products
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
Used in attacksAdded to CISA's list 2026-09-24 · Patch or advisory available
Full record →
Fastnexa security experts
This story involves a flaw attackers are already using. Are you exposed?
A Fastnexa penetration tester can check whether CVE-2026-5430 or anything like it can be used against your websites, apps and network.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-25 17:24 UTC
Related stories
- Apple patches CoreGraphics zero-day flaw exploited in attacks
BleepingComputer · 2026-09-29
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The Hacker News · 2026-09-29
- OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
The Hacker News · 2026-09-29
- One Packet Can Crash OT Servers in Industrial Sectors
Dark Reading · 2026-09-28