The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified and added two significant security vulnerabilities affecting WSO2 and Adobe Commerce to its Known Exploited Vulnerabilities (KEV) catalog. This action, announced on Thursday, follows confirmed reports of active exploitation of these vulnerabilities.
Details of the WSO2 and Adobe Vulnerabilities
Two key vulnerabilities have been highlighted by CISA. The first, cataloged as CVE-2026-5430, presents a path traversal issue within the WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. This flaw, with a critical severity score of 9.8, can potentially allow unauthorized file uploads, leading to remote code execution.
The second vulnerability, CVE-2026-71362, affects Adobe Commerce and Magento platforms. It holds a CVSS score of 9.1 due to incorrect authorization protocols that attackers can exploit to gain elevated access to sensitive resources, without requiring user interaction.
Ongoing Exploitation Reports
The vulnerability affecting WSO2 has been actively targeted since at least September 13, 2026, according to cybersecurity firm watchTowr. Concurrently, Sansec, a Dutch e-commerce security company, reported in August 2026 that attempts to exploit the Adobe Commerce flaw had been detected and blocked.
Sansec further explained that the vulnerability enables attackers to hijack customer sessions, granting them access to accounts and sensitive customer data. Reports indicate that an attempt to exploit this vulnerability was detected from an Australian IP address targeting honeypot systems on September 10, 2026.
Urgent Mitigation Measures for Agencies
CISA has advised Federal Civilian Executive Branch (FCEB) agencies to implement fixes for these vulnerabilities by September 27, 2026. This directive is part of efforts to protect networks from ongoing threats and prevent unauthorized access to sensitive resources.
Despite these developments, Adobe has not yet confirmed whether the exploitation of this vulnerability has been officially recognized in their advisory updates. Organizations using the affected platforms are urged to stay vigilant and apply necessary security patches promptly.
These vulnerabilities underscore the critical importance of maintaining robust security protocols within digital infrastructures and the need for timely response to emerging cyber threats.
