
WSO2 and Adobe Commerce Flaws Exploited in Real Attacks, Added to CISA KEV
CISA has added two critical vulnerabilities affecting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities catalog, citing active exploitation. Federal agencies must patch by September 27, 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities affecting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, based on evidence of active exploitation.
The WSO2 path traversal flaw
The first entry, CVE-2026-5430, carries a CVSS score of 9.8. It is a path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remote code execution. The listing came a little over a week after the security firm watchTowr said it had observed in-the-wild exploitation attempts against its honeypots since at least September 13.
Adobe Commerce account takeover
The second flaw, CVE-2026-71362, is rated 9.1. It is an incorrect authorization vulnerability in Adobe Commerce and Magento that could let an attacker gain elevated access to sensitive resources without any user interaction. The Dutch e-commerce security company Sansec said in August 2026 that it had detected and blocked exploitation attempts. “The vulnerability lets attackers switch a customer session to another customer account,” Sansec said. “This gives them access to the victim’s account and private customer data.” Previdian’s telemetry indicates that a lone IP address from Australia tried to exploit the flaw against its honeypot sensors on September 10, 2026. Adobe has yet to update its advisory to confirm the exploitation status.
What the KEV listing means
The Known Exploited Vulnerabilities catalog is the U.S. government’s list of bugs that attackers use in real campaigns. Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026. For everyone else the catalog works as a priority signal: these are no longer theoretical risks, and internet-facing systems running the affected products should be patched on the same schedule.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.