The Cybersecurity and Infrastructure Security Agency (CISA) has added two critical-severity vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation, one affecting WSO2 enterprise software products and another impacting Adobe Commerce and Magento.
WSO2 Path Traversal Enables Authentication Bypass
CVE-2026-5430 (CVSS 9.8) is a path traversal vulnerability in WSO2 API Manager (versions 4.1.0 through 4.6.0), API Control Plane, Traffic Manager, and Universal Gateway (versions 4.5.0 and 4.6.0). According to WSO2’s original advisory, the flaw stems from the JWT authentication mechanism accepting tokens signed with an unsupported algorithm, allowing attackers to forge tokens and compromise administrative accounts for full system takeover.
Security firm watchTowr said its honeypots captured exploitation attempts on September 13, with a limited number of tries from a single IP address using forged JWT tokens. The attacker initially targeted the wrong WSO2 product, but watchTowr researchers reproduced the attack against the correct target, confirming that a forged token could expose API endpoints and application credentials.
watchTowr threat intelligence specialist Yordan Ganchev noted that WSO2 technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics, arguing that organizations in these sectors cannot afford to wait for exploitation to be formally confirmed before patching.
Adobe Commerce Flaw Requires No Authentication
CVE-2026-71362 is an incorrect authorization vulnerability in Adobe Commerce and Magento. Ecommerce security firm Sansec observed active exploitation in the wild and reported that attackers need no existing account, administrator privileges, or user interaction to leverage the flaw.
Additional Flaws Under Active Exploitation
CISA also flagged two other vulnerabilities being exploited: a high-severity code injection bug in Microsoft SharePoint (CVE-2026-65660) and a medium-severity pre-authentication SSH state-machine bypass in Mikrotik RouterOS (CVE-2026-67279).
Remediation Deadline
Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must apply patches or mitigations for the two critical KEV entries, or discontinue use of the affected products, by Sunday, September 27. The directive also requires agencies to check whether systems were compromised before patches were applied. While the mandate applies only to federal agencies, CISA is urging all organizations to prioritize remediation given the severity and confirmed exploitation of these flaws.
