Security & privacy

CISA adds actively exploited WSO2 and Adobe Commerce flaws to KEV catalog

CISA added two critical vulnerabilities in WSO2 and Adobe Commerce to its Known Exploited Vulnerabilities catalog due to active attacks.

A cracked digital shield protecting servers from attack arrows
Illustration created for this article

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical security flaws affecting WSO2 and Adobe Commerce to its Known Exploited Vulnerabilities (KEV) catalog on Thursday. This action follows confirmed evidence that threat actors are actively exploiting these weaknesses in live environments, prompting urgent remediation advice for federal agencies and private sector operators alike.

What happened

The first vulnerability, tracked as CVE-2026-5430, carries a CVSS score of 9.8. It is a path traversal flaw found in several WSO2 components, including the API Control Plane, API Manager, Traffic Manager, and Universal Gateway. Successful exploitation allows an attacker to upload files without restriction, which can lead to remote code execution on the affected server. The second issue, CVE-2026-71362, has a CVSS score of 9.1 and affects Adobe Commerce and Magento. This incorrect authorization bug enables attackers to gain elevated access to sensitive resources without any user interaction.

Evidence of active exploitation for the WSO2 flaw emerged quickly. Security firm watchTowr reported observing in-the-wild exploitation attempts against its honeypots starting at least on September 13, 2026. Researchers captured forged JWT tokens targeting the vulnerability and reproduced the exploit themselves, confirming that attackers were acting on the flaw before public technical details were widely available. Yordan Ganchev, a principal threat intelligence specialist at watchTowr, noted that "attackers already have days, or, in this instance, weeks, to act" by the time a vulnerability reaches the KEV catalog.

For the Adobe Commerce and Magento vulnerability, Dutch e-commerce security company Sansec detected and blocked exploitation attempts in August 2026. The flaw allows attackers to switch a customer session to another user's account, granting access to private data. Additionally, telemetry from Previdian showed a single IP address from Australia attempting to exploit this flaw against their honeypot sensors on September 10, 2026. While Adobe has not yet updated its advisory to formally confirm the exploitation status, the presence of these attempts in multiple independent feeds suggests coordinated activity.

Key details

  • CISA added CVE-2026-5430 (WSO2) and CVE-2026-71362 (Adobe Commerce/Magento) to the KEV catalog on Thursday.
  • CVE-2026-5430 is a path traversal vulnerability with a CVSS score of 9.8, allowing unrestricted file upload and remote code execution.
  • CVE-2026-71362 is an incorrect authorization vulnerability with a CVSS score of 9.1, enabling session hijacking and unauthorized data access.
  • WatchTowr observed active exploitation of the WSO2 flaw using forged JWT tokens as early as September 13, 2026.
  • Sansec blocked exploitation attempts for the Adobe flaw in August 2026, noting it allows switching customer sessions.
  • Federal Civilian Executive Branch (FCEB) agencies must apply fixes for both vulnerabilities by September 27, 2026.

Background

The Known Exploited Vulnerabilities (KEV) catalog is a living list maintained by CISA that tracks vulnerabilities with known active exploitation. Unlike general vulnerability databases that list every possible weakness, the KEV catalog focuses on threats that are currently being used by attackers in the wild. Inclusion in this catalog triggers mandatory remediation timelines for U.S. federal agencies and serves as a high-priority signal for private organizations. The goal is to reduce the window of opportunity for attackers by forcing rapid patching of the most dangerous, actively used flaws.

Path traversal vulnerabilities allow attackers to navigate outside the intended directory structure of a web application, often leading to unauthorized file access or upload. Incorrect authorization flaws, such as the one in Adobe Commerce, occur when the system fails to properly verify if a user has permission to perform a specific action or access specific data. In e-commerce platforms, this can be particularly devastating, as it may allow one user to view or modify another user's order history, personal information, or payment details without needing their credentials.

Why it matters

For teams running self-hosted instances of WSO2 or Adobe Commerce, this news indicates an immediate and tangible risk. The fact that exploitation was observed weeks before the formal KEV listing means that many organizations may have been exposed during that gap. WSO2 is widely used in critical sectors like banking, government, and telecommunications, making it a high-value target. Delaying patches until a formal advisory is updated or until internal scanning tools catch up could leave systems open to remote code execution, which is often a precursor to ransomware deployment or data exfiltration.

The Adobe Commerce flaw highlights the danger of silent account takeovers. Because the vulnerability requires no user interaction, victims will not know their session has been hijacked until they notice unauthorized changes or data leaks. For mid-sized companies managing their own e-commerce infrastructure, this poses a significant liability risk. Customer trust is fragile, and a breach involving private data access can have long-term reputational damage beyond the immediate technical cleanup. The speed at which attackers moved from discovery to exploitation underscores the need for proactive monitoring rather than reactive patching.

What you can do

  • Patch all WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway instances immediately to address CVE-2026-5430.
  • Apply the latest security updates for Adobe Commerce and Magento to fix CVE-2026-71362, even if Adobe has not formally confirmed exploitation in their advisory.
  • Review web server logs for unusual file upload activities or unexpected JWT token usage patterns since mid-September 2026.
  • Audit customer session logs for signs of session switching or unauthorized access to user accounts in your e-commerce platform.
  • Ensure your intrusion detection systems are tuned to flag path traversal attempts and abnormal authorization requests.
  • Verify that your backup systems are isolated and up-to-date to facilitate rapid recovery in case of successful exploitation.

More news

All news