[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVgPVI8P1qWSZm7HIriTBSPNInjuw3MglyKyvMdknaW0":3},{"article":4,"iocs":46},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"4a04d914-7267-40f6-910d-4b17f8cad998","WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV","wso2-and-adobe-commerce-flaws-exploited-in-attacks-added-to-cisa-kev-9b34a9","The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,","CISA has added two critical vulnerabilities, CVE-2026-5430 affecting WSO2 API Control Plane and CVE-2026-71362 impacting Adobe Commerce and Magento, to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities are being actively exploited in the wild, with WatchTowr observing exploitation attempts since September 13, 2026, and Sansec detecting exploitation for CVE-2026-71362 in August 2026. Federal agencies are urged to patch these flaws by September 27, 2026.","CISA adds WSO2 and Adobe Commerce flaws to KEV catalog due to active exploitation.","WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV Ravie LakshmananSep 25, 2026Vulnerability \u002F Web Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remote code execution. CVE-2026-71362 (CVSS score: 9.1) - An incorrect authorization vulnerability in Adobe Commerce and Magento that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026. As for CVE-2026-71362, Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw. \"The vulnerability lets attackers switch a customer session to another customer account,\" the Dutch e-commerce security company said. \"This gives them access to the victim's account and private customer data.\" Previdian's telemetry indicates that a lone IP address from Australia attempted to exploit the flaw targeting its honeypot sensors on September 10, 2026. Adobe has yet to update its advisory to confirm exploitation status. Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Adobe, API Security, E-commerce Security, Magento, Vulnerability, Web Security ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fwso2-and-adobe-commerce-flaws-exploited.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgqTAzyCx7Cezy4z5oRz-uAHvdvW1IZDrQlfIqT_ZDJ22Hvarb4lmYWkjqBDI_CngiSy2wuot68b2CgMS_0CWVZS93lYo5wqJsd5-WdFQgO3dieodXpVQiizcFjQsPzUOlVrs32zkBaHAwOyD7S4GCZ3b1d-Jyt4-ZTaMltfU0jG5dwBw5cxj880D4Cx8W0\u002Fs1600\u002FADOBE-CISA.jpg","2026-09-25T04:46:34+00:00","2026-09-25T08:00:11.594762+00:00",9,[18,21,23,25,28,30],{"name":19,"type":20},"WSO2 API Control Plane","product",{"name":22,"type":20},"Adobe Commerce",{"name":24,"type":20},"Magento",{"name":26,"type":27},"WSO2","vendor",{"name":29,"type":27},"Adobe",{"name":31,"type":32},"API Security","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":33,"icon":35,"name":36,"slug":37},null,"Vulnerabilities","vulnerabilities",[39,41],{"category":40},{"id":33,"icon":35,"name":36,"slug":37},{"category":42},{"id":43,"icon":35,"name":44,"slug":45},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[47,51],{"type":48,"value":49,"context":50},"cve","CVE-2026-5430","Path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway.",{"type":48,"value":52,"context":53},"CVE-2026-71362","Incorrect authorization vulnerability in Adobe Commerce and Magento."]