Skip to main content
Emerging Threats

CISA Flags WSO2, Adobe Commerce Flaws as Actively Exploited

Technicians monitor equipment and check a laptop in a brightly-lit server room.

Federal Civilian Executive Branch agencies are advised to apply fixes for both vulnerabilities by September 27, 2026.

CVE-2026-5430: WSO2 path traversal that can lead to remote code execution

On Thursday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-5430 to its Known Exploited Vulnerabilities (KEV) catalog “based on evidence of active exploitation.” The vulnerability, with a CVSS score of 9.8, is a path traversal flaw affecting WSO2 components including API Control Plane, API Manager, Traffic Manager and Universal Gateway. According to the advisory language in the source, the flaw could allow unrestricted file upload and lead to remote code execution.

CVE-2026-71362: Adobe Commerce and Magento incorrect authorization

CISA also added CVE-2026-71362 (CVSS score: 9.1) to the KEV list. The vulnerability is described as an incorrect authorization bug in Adobe Commerce and Magento that could allow an attacker to “gain elevated access to sensitive resources without any user interaction.” Dutch e-commerce security company Sansec summarized the effect in plain terms: “The vulnerability lets attackers switch a customer session to another customer account,” giving them access to the victim’s account and private customer data.

Detected exploitation: watchTowr, Sansec and Previdian telemetry

Multiple external observers reported exploitation activity prior to the KEV additions. watchTowr reported seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026 — a timeline CISA’s listing follows by a little over a week for the WSO2 flaw. Sansec said in August 2026 that it had detected and blocked exploitation attempts targeting the Adobe Commerce/Magento issue. Previdian’s telemetry indicated that a lone IP address from Australia attempted to exploit the Adobe flaw against its honeypot sensors on September 10, 2026. The source notes that Adobe has yet to update its advisory to confirm exploitation status.

CISA KEV addition and the September 27, 2026 FCEB deadline

By placing both CVE-2026-5430 and CVE-2026-71362 in the KEV catalog, CISA signals the agency’s view that credible, observed exploitation is occurring and that federal networks face an elevated risk if patches are not applied. The bulletin sets a specific mitigation milestone: Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to protect networks against active threats.

What this means for technologists, FCEB agencies, and e-commerce merchants

  • Technologists and security teams: Prioritize verification and patching for deployments of WSO2 API components and for Adobe Commerce/Magento instances. The WSO2 defect permits unrestricted file upload and can escalate to remote code execution; the Adobe/Magento authorization bug enables account session switching and exposure of private customer data.
  • FCEB agencies: The advisory imposes a near-term compliance action — apply fixes by September 27, 2026 — and monitor for indicators tied to the exploitation reports from watchTowr, Sansec and Previdian.
  • E-commerce merchants and operators of Magento/Adobe Commerce: Take the session-switching report from Sansec seriously — blocked attempts were observed in August 2026 and a probe from an Australian IP was recorded on September 10, 2026 — and confirm whether vendor advisories and patches have been applied in production to reduce customer data exposure.

Two things stand out from the record supplied to CISA: first, defenders have already observed exploitation activity against both flaws; second, the agency has set an explicit near-term remediation deadline for federal agencies. Adobe’s lack of an updated advisory confirming exploitation status remains an open detail in the timeline. Whether additional telemetry will emerge in the days after the KEV additions will determine how rapidly organizations outside the federal domain escalate mitigations.

Original story