Full Report
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,
Analysis Summary
# Morning News Roll-up September 26, 2026
## Overview
CISA has added two critical vulnerabilities impacting WSO2 and Adobe Commerce/Magento to its Known Exploited Vulnerabilities (KEV) catalog. Both flaws are currently being targeted in the wild, enabling remote code execution and unauthorized account access.
## Top Stories
### WSO2 Path Traversal and RCE Flaw (CVE-2026-5430)
- Summary: A critical path traversal vulnerability in WSO2 API management products allows for unrestricted file uploads, which can be leveraged to achieve remote code execution (RCE). Exploitation attempts have been recorded in the wild since mid-September.
- Source: hxxps://thehackernews[.]com/2026/09/wso2-and-adobe-commerce-flaws-exploited[.]html
### Adobe Commerce and Magento Account Takeover (CVE-2026-71362)
- Summary: An incorrect authorization flaw allows attackers to bypass security measures and switch customer sessions. This enables unauthorized access to sensitive customer data and account takeovers without requiring user interaction.
- Source: hxxps://thehackernews[.]com/2026/09/active-exploitation-attempts-target[.]html
### CISA KEV Update and Federal Compliance
- Summary: CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies patch these vulnerabilities by September 27, 2026. Evidence from security firms like watchTowr and Sansec confirms active exploitation of these specific flaws.
- Source: hxxps://www[.]cisa[.]gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog
---
# Main Topic
CISA warns of active exploitation of critical vulnerabilities in WSO2 API management solutions and Adobe e-commerce platforms, adding them to the Known Exploited Vulnerabilities (KEV) catalog.
## Key Points
- **CVE-2026-5430 (CVSS 9.8):** A path traversal flaw in WSO2 products that facilitates unrestricted file uploads and subsequent remote code execution.
- **CVE-2026-71362 (CVSS 9.1):** An authorization bypass in Adobe Commerce and Magento allowing attackers to hijack customer sessions.
- **Active Exploitation:** watchTowr reported honeypot activity for WSO2 starting September 13, 2026. Sansec and Previdian reported Adobe exploitation attempts as early as August and September 2026.
- **Urgency:** CISA has set a short deadline for federal agencies to remediate these flaws due to the high risk of data theft and system compromise.
## Threat Actors
- **Unnamed Australian Actor:** Telemetry from Previdian identified a lone IP address originating from Australia targeting Adobe Commerce honeypots on September 10, 2026.
- **General Cybercriminals:** Exploitation of CVE-2026-71362 is primarily motivated by the theft of private customer data and e-commerce account takeovers.
## TTPs
- **Path Traversal:** Used in WSO2 attacks to bypass directory restrictions and upload malicious files.
- **Session Hijacking:** Attackers leverage incorrect authorization in Magento to switch a legitimate customer session to another account.
- **Zero-Interaction Exploits:** The Adobe vulnerability can be exploited without any victim participation.
- **Honeypot Targeting:** Actors are actively scanning the internet for unpatched instances of these specific services.
## Affected Systems
- **WSO2:** API Control Plane, API Manager, Traffic Manager, and Universal Gateway.
- **Adobe:** Adobe Commerce and Magento Open Source.
- **Impact:** Potential for full system takeover (WSO2) and massive data breaches involving sensitive customer information (Adobe/Magento).
## Mitigations
- **Patch Management:** Immediate application of security updates provided by WSO2 and Adobe.
- **FCEB Compliance:** Federal agencies must apply fixes by the September 27, 2026, deadline.
- **Session Monitoring:** Implement enhanced monitoring for suspicious session-switching behavior in e-commerce environments.
- **Ingress Filtering:** Block known malicious IPs identified in telemetry reports (e.g., those flagged by Previdian).
## Conclusion
The inclusion of these vulnerabilities in the CISA KEV catalog underscores a significant and immediate threat to organizations using WSO2 and Adobe Commerce. Organizations should prioritize patching these flaws immediately, as the window between disclosure and active exploitation has narrowed significantly, with attackers already actively compromising vulnerable instances for data exfiltration and code execution.