Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

Дата публикации: 25-09-2026 04:46:34

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerabilities are listed below -
CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in  WSO2 API Control Plane,

Основное содержимое страницы с новостью.

Ravie LakshmananSep 25, 2026Vulnerability / Web Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The vulnerabilities are listed below -

  • CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in  WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remote code execution.
  • CVE-2026-71362 (CVSS score: 9.1) - An incorrect authorization vulnerability in  Adobe Commerce and Magento that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026.

"We captured forged JWT tokens targeting the flaw on September 13 and reproduced the vulnerability ourselves, despite the lack of public technical details," Yordan Ganchev, principal threat intelligence specialist at watchTowr, said in a statement. "That gave us direct evidence that this wasn't merely a theoretical vulnerability or a critical severity score on paper. It was exploitable, and attackers were already acting on it. "

"It's worth reiterating that WSO2 isn't a niche target. Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics. Organizations in these sectors can't afford to wait for exploitation to be formally confirmed. By the time a vulnerability reaches the KEV catalog, attackers already have days, or, in this instance, weeks, to act."

As for CVE-2026-71362, Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw.

In a statement shared with The Hacker News, a WSO2 spokesperson said the company alerted customers and provided the necessary security updates on April 6, 2026, and released a public advisory on May 3, 2026. "At present, we have not identified any impact on customers who applied the recommended updates," the spokesperson added. "We will continue to monitor the situation and flag further action as available."

"The vulnerability lets attackers switch a customer session to another customer account," the Dutch e-commerce security company said. "This gives them access to the victim's account and private customer data."

Previdian's telemetry indicates that a lone IP address from Australia attempted to exploit the flaw targeting its honeypot sensors on September 10, 2026. Adobe has yet to update its advisory to confirm exploitation status. 

Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats.

(The story was updated after publication on September 29, 2026, to include a response from WSO2.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally07.6328-09-2026
2Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager09.9530-09-2026
3SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild06.826-09-2026
4Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation09.2627-09-2026
5Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT07.930-09-2026
6Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution08.3930-09-2026
7Know Your Enemy: Browser-Based Attack Techniques in 2026010.130-09-2026
8WordPress CVE-2026-87902 Under Active Attack: Critical RCE Flaw Exploited Within Hours013.5924-09-2026
9Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets09.230-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 9.71. Источник: thehackernews.com.