WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
At a glance
- Severity
- CriticalCVSS 10.0
- Used in attacks
- Yes, 1 of 1 flaw named
- Flaws named
- CVE-2026-5430
- Vendors and products
- Adobe
- Industries
- Retail & e-commerceGovernment
- Reported by
- 1 outlet
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerabilities are listed below -
- CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remote code execution.
- CVE-2026-71362 (CVSS score: 9.1) - An incorrect authorization vulnerability in Adobe Commerce and Magento that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026.
As for CVE-2026-71362, Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw.
"The vulnerability lets attackers switch a customer session to another customer account," the Dutch e-commerce security company said. "This gives them access to the victim's account and private customer data."
Previdian's telemetry indicates that a lone IP address from Australia attempted to exploit the flaw targeting its honeypot sensors on September 10, 2026. Adobe has yet to update its advisory to confirm exploitation status.
Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats.
Reproduced in full under licence from The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).
Vulnerabilities referenced
- CVE-2026-543010.0Critical
Wso2 Api Control Plane
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.
Used in attacksAdded to CISA's list 2026-09-24 · Patch or advisory available
Full record →
Coverage
One outlet has carried this so far.
2026-09-25 04:46 UTC
Related stories
- Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
Infosecurity Magazine · 2026-09-25
- CISA Unveils Election Security Plan Ahead of 2026 Midterms
Infosecurity Magazine · 2026-09-25
- The SOC Doesn't Need to Start Over with Every Alert
The Hacker News · 2026-09-25
- Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Hacker News · 2026-09-25
- Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
The Hacker News · 2026-09-25