Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WSO2 and Adobe Flaws Exploited, CISA Alerts

Critical WSO2 and Adobe Flaws Exploited, CISA Alerts

Posted on September 25, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified and added two significant security vulnerabilities affecting WSO2 and Adobe Commerce to its Known Exploited Vulnerabilities (KEV) catalog. This action, announced on Thursday, follows confirmed reports of active exploitation of these vulnerabilities.

Details of the WSO2 and Adobe Vulnerabilities

Two key vulnerabilities have been highlighted by CISA. The first, cataloged as CVE-2026-5430, presents a path traversal issue within the WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. This flaw, with a critical severity score of 9.8, can potentially allow unauthorized file uploads, leading to remote code execution.

The second vulnerability, CVE-2026-71362, affects Adobe Commerce and Magento platforms. It holds a CVSS score of 9.1 due to incorrect authorization protocols that attackers can exploit to gain elevated access to sensitive resources, without requiring user interaction.

Ongoing Exploitation Reports

The vulnerability affecting WSO2 has been actively targeted since at least September 13, 2026, according to cybersecurity firm watchTowr. Concurrently, Sansec, a Dutch e-commerce security company, reported in August 2026 that attempts to exploit the Adobe Commerce flaw had been detected and blocked.

Sansec further explained that the vulnerability enables attackers to hijack customer sessions, granting them access to accounts and sensitive customer data. Reports indicate that an attempt to exploit this vulnerability was detected from an Australian IP address targeting honeypot systems on September 10, 2026.

Urgent Mitigation Measures for Agencies

CISA has advised Federal Civilian Executive Branch (FCEB) agencies to implement fixes for these vulnerabilities by September 27, 2026. This directive is part of efforts to protect networks from ongoing threats and prevent unauthorized access to sensitive resources.

Despite these developments, Adobe has not yet confirmed whether the exploitation of this vulnerability has been officially recognized in their advisory updates. Organizations using the affected platforms are urged to stay vigilant and apply necessary security patches promptly.

These vulnerabilities underscore the critical importance of maintaining robust security protocols within digital infrastructures and the need for timely response to emerging cyber threats.

The Hacker News Tags:Adobe Commerce, authorization flaw, CISA, Cybersecurity, Exploitation, FCEB, KEV, path traversal, Vulnerabilities, web security, WSO2

Post navigation

Previous Post: Cloudflare Secures Containers Against Data Leak Vulnerability
Next Post: Roundcube Vulnerability Targeted by Cyber Attackers

Related Posts

Anthropic AI Unearths Firefox Security Flaws Anthropic AI Unearths Firefox Security Flaws The Hacker News
BlueNoroff Targets Crypto Wallets via Phishing on Zoom BlueNoroff Targets Crypto Wallets via Phishing on Zoom The Hacker News
CISA Adds Three Exploited Vulnerabilities to KEV Catalog Affecting Citrix and Git CISA Adds Three Exploited Vulnerabilities to KEV Catalog Affecting Citrix and Git The Hacker News
Cyber Attacks Exploit WinRAR Flaw Against Ukraine Cyber Attacks Exploit WinRAR Flaw Against Ukraine The Hacker News
Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets The Hacker News
Top 10 Best Practices for Effective Data Protection Top 10 Best Practices for Effective Data Protection The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • MacSync Malware Targets macOS for Crypto and Data Theft
  • Roundcube Vulnerability Targeted by Cyber Attackers
  • Critical WSO2 and Adobe Flaws Exploited, CISA Alerts
  • Cloudflare Secures Containers Against Data Leak Vulnerability
  • Cloudflare Secures Containers After Disk Data Exposure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • MacSync Malware Targets macOS for Crypto and Data Theft
  • Roundcube Vulnerability Targeted by Cyber Attackers
  • Critical WSO2 and Adobe Flaws Exploited, CISA Alerts
  • Cloudflare Secures Containers Against Data Leak Vulnerability
  • Cloudflare Secures Containers After Disk Data Exposure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark