The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added two severe security vulnerabilities affecting WSO2 and Adobe Commerce (including Magento) to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed evidence of malicious activity. Both vulnerabilities carry high-risk scores and are now under active exploitation. Federal Civilian Executive Branch agencies have been instructed to patch these flaws by September 27, 2026, to avoid further risk.
Vulnerability Details
The first flaw, CVE-2026-5430 (CVSS score: 9.8), exists in WSO2’s API Control Plane, API Manager, Traffic Manager, and Universal Gateway. It’s a path traversal issue that allows attackers to upload arbitrary files without restriction, leading potentially to remote code execution. Reports of this vulnerability being exploited in the wild date back to at least September 13, 2026, as seen in honeypot systems monitored by watchTowr.
The second vulnerability, CVE-2026-71362 (CVSS score: 9.1), is an authorization bypass in Adobe Commerce and Magento. It enables attackers to elevate privileges and access sensitive resources across customer accounts, without any user interaction. Sansec detected and prevented exploitation attempts in August 2026, while prepaid honeypot sensors recorded activity targeting this flaw from an IP in Australia on September 10.
Scope, Impact, and Urgency
These two vulnerabilities pose grave risks—WSO2’s flaw (CVE-2026-5430) allows attackers to execute code remotely, and the Adobe Commerce flaw (CVE-2026-71362) permits unauthorized access to private customer data. That’s especially alarming for e-commerce platforms where customer privacy and transactional integrity are critical. Since exploitation has been observed in both cases, the urgency for quick mitigation is high.
The federal directive requiring fixes by September 27 underscores the severity and confirms that these threats are not theoretical; they are currently being leveraged in real-world attacks. While Adobe has yet to issue an advisory confirming exploit status for CVE-2026-71362, independent security firms report already blocking malicious activity tied to it.
For organizations relying on WSO2 and Adobe Commerce technologies, this means immediate action is essential. Applying patches, updating to secure versions, and auditing configurations are not optional—they’re vital defenses against ongoing compromise.
The addition of these vulnerabilities to CISA’s KEV list makes them required risk mitigations for U.S. government agencies. Outside the government, businesses should treat this alert as a critical warning sign. Any delay in addressing these security flaws could lead to data breaches, loss of trust, and serious legal liability.
What to watch for: whether Adobe formally confirms exploited status for CVE-2026-71362; reports of further exploit activity; and updates to mitigation guidance or patch releases. Organizations should also check for attempts to switch session identities, unauthorized access, or any odd file uploads in their logs—signs that an exploit may be underway.
This development continues the trend of attackers rapidly targeting known vulnerabilities soon after discovery. The timeline for detection and exploitation here—sometimes within days—reinforces that patching strategies must match the speed of threat actors.
Analysis: These highly rated flaws highlight a critical gap between vulnerability disclosure and operational risk management. For platforms like WSO2 and Adobe Commerce, the window between discovering or being notified of a vulnerability and seeing it exploited is shrinking dramatically. Organizations must adopt continuous monitoring, faster patch application, and rigorous controls, especially around authorization checks and file handling. Failing to do so means inviting active attacks already in progress across industries and geographies.