“Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics,” explained Yordan Ganchev, and “Organizations in these sectors can't afford to wait for exploitation to be formally confirmed.”
CVE-2026-5430: critical authentication bypass in WSO2 products
The Cybersecurity and Infrastructure Security Agency (CISA) warns that attackers are exploiting CVE-2026-5430, a critical authentication-bypass vulnerability that carries a maximum severity score and affects multiple WSO2 products. The flaw impacts WSO2 API Manager versions 4.1.0 through 4.6.0, and API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
The vendor's original advisory on May 3 stated that a successful exploit “could compromise administrative accounts and take full control.” CISA noted the problem stems from the JWT authentication mechanism accepting tokens signed with an unsupported algorithm.
Security firm watchTowr reported on September 15 that its honeypots captured exploitation attempts. Researchers said they observed a limited number of attempts from one IP address on September 13 using forged JWT tokens against a WSO2 product; the attacker initially targeted the wrong product. watchTowr reproduced the attack on the correct product and found a forged token could expose API endpoints and application credentials.
CVE-2026-71362: incorrect authorization in Adobe Commerce and Magento
CISA also added CVE-2026-71362, a critical incorrect-authorization vulnerability in Adobe Commerce and Magento, to its Known Exploited Vulnerabilities (KEV) catalog. Ecommerce security company Sansec observed CVE-2026-71362 being exploited in the wild and warned that threat actors require “no existing account, administrator privileges, or user interaction” to leverage it.
Because exploitation has been observed, CISA placed the vulnerability on the KEV list to drive prioritization and mitigation across affected environments.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleMicrosoft SharePoint CVE-2026-65660 and Mikrotik RouterOS CVE-2026-67279
Alongside the two critical bugs, CISA named two additional vulnerabilities being exploited in attacks. The agency identified a high-severity code-injection flaw in Microsoft SharePoint tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS as CVE-2026-67279.
CISA has not shared operational details about the attacks leveraging these vulnerabilities; its bulletin focuses on listing the affected products and accelerating mitigation timelines.
CISA deadlines for federal agencies and recommended actions
For the two critical issues added to the KEV — CVE-2026-5430 (WSO2) and CVE-2026-71362 (Adobe Commerce/Magento) — federal agencies using the affected products have until Sunday, September 27, to apply the recommended updates or mitigations, or discontinue their use. For the SharePoint and Mikrotik flaws, agencies have until Monday, September 28, to remediate.
CISA also “encourages all organizations to take action and prioritize addressing the security issues listed in the KEV.” The agency’s directive frames the options concretely: apply vendor updates or mitigations, or discontinue use of vulnerable components when those steps are not feasible.
What this means for federal agencies, WSO2 customers, and e-commerce operators
- Federal agencies: The KEV deadlines require a short-window operational response — apply updates or mitigations, or remove affected products by September 27 or 28 as specified.
- WSO2 customers in banking, government, telecommunications, and logistics: watchTowr’s assessment and the vendor’s May 3 advisory mean organizations using the named versions should treat administrative-account compromise and full takeover as credible risks and prioritize patching or mitigation.
- E-commerce operators using Adobe Commerce/Magento: Sansec’s observation that CVE-2026-71362 can be exploited with “no existing account, administrator privileges, or user interaction” signals elevated urgency for patching, mitigation, or temporary discontinuation of exposed services until fixes are applied.
CISA’s additions to the KEV catalog compress the time available to react. Public reporting shows limited but real exploitation activity: watchTowr’s honeypot captures and Sansec’s field observations. With vendor advisories already describing high-impact outcomes — including the potential to “compromise administrative accounts and take full control” — the record in hand leaves little ambiguity about the immediate operational imperative: locate affected instances, apply vendor-recommended updates or mitigations, or remove the software from production until it is safe.




