CISA Adds Actively Exploited WSO2 and Adobe Flaws to KEV

CISA Adds Actively Exploited WSO2 and Adobe Flaws to KEV

Federal agencies must patch critical authentication bypasses in WSO2 API Manager and Adobe Commerce by September 27 after CISA confirmed active exploitation.

The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog with two critical security flaws that threat actors are actively leveraging in the wild. The agency issued an urgent directive for federal agencies to apply patches or mitigate these specific weaknesses by Sunday, September 27, citing immediate risks to organizational infrastructure.

The first vulnerability added to the list is CVE-2026-5430, a critical authentication bypass flaw affecting multiple products from enterprise software provider WSO2. This issue impacts WSO2 API Manager versions 4.1.0 through 4.6.0, as well as the API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. According to the vendor advisory released on May 3, the defect stems from the JSON Web Token (JWT) authentication mechanism incorrectly accepting tokens signed with unsupported algorithms. An attacker who successfully exploits this flaw can compromise administrative accounts and gain full control over the affected systems. The severity score for this vulnerability is at the maximum level, reflecting the high risk it poses to enterprise environments.

Security researchers at watchTowr provided early evidence of exploitation before CISA’s formal warning. On September 15, the firm announced that its honeypots had captured attempts to exploit CVE-2026-5430. The researchers observed a limited number of attempts originating from a single IP address on September 13. Although the initial attack targeted the wrong product variant, watchTowr successfully reproduced the exploit against the correct WSO2 product. Their testing demonstrated that a forged token could expose API endpoints and application credentials. Yordan Ganchev, a threat intelligence specialist at watchTowr, emphasized that WSO2 is not a niche target. He noted that the technology serves nearly 1,000 customers across banking, government, telecommunications, and logistics sectors, making rapid remediation essential for organizations that cannot afford to wait for formal confirmation of widespread exploitation.

The second critical vulnerability added to the KEV catalog is CVE-2026-71362, which affects Adobe Commerce and Magento e-commerce platforms. This flaw involves incorrect authorization checks that allow attackers to leverage the bug without requiring an existing account, administrator privileges, or any user interaction. E-commerce security company Sansec observed CVE-2026-71362 being exploited in production environments, highlighting the ease with which threat actors can take advantage of this weakness. The lack of prerequisites for exploitation makes this particularly dangerous for online retailers relying on these platforms.

In addition to the two critical issues, CISA also identified two other vulnerabilities currently being exploited in attacks. These include a high-severity code injection flaw in Microsoft SharePoint, tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine and workflow bypass in Mikrotik RouterOS, identified as CVE-2026-67279. Federal agencies have been given until Monday, September 28 to fix these specific issues. While the strict deadline applies to government entities, CISA encourages all organizations to prioritize addressing the security issues listed in the KEV catalog to reduce their exposure to known threats.

For website owners and IT teams managing hosted environments, these alerts underscore the importance of keeping core software components updated. Managed hosting providers often handle the underlying infrastructure, but application-layer vulnerabilities in platforms like Adobe Commerce or custom integrations using WSO2 APIs require specific attention. Ensuring that your hosting environment supports timely patching and that you monitor for updates to these specific enterprise tools is crucial for maintaining security posture against actively exploited flaws.

If you rely on managed WordPress hosting or secure cloud infrastructure for your business operations, AEU Hosting provides end-to-end secured managed WordPress hosting solutions designed to help you stay protected against such emerging threats by ensuring your environment remains up-to-date and resilient.

So schützen Sie sich

  1. Update your WSO2 API Manager and gateway software to version 4.6.0 or later immediately if you use these enterprise tools.
  2. Apply the latest security patches for Adobe Commerce or Magento to fix the authorization bypass vulnerability.
  3. Ensure your Microsoft SharePoint installation is updated to address the code injection flaw CVE-2026-65660.
  4. Patch your Mikrotik RouterOS devices to close the SSH state-machine bypass identified in CVE-2026-67279.
  5. Monitor your server logs for unusual authentication attempts or unauthorized access patterns to detect potential exploitation early.

Schwachstellen & Lösungen

Verwandte AEU-Dienste

  • AEU-I IT- und Sicherheitsberatung