Skip to content

CISA Adds WSO2 and Adobe Commerce Flaws to Its Known Exploited Vulnerabilities Catalog

CISA adds two actively exploited flaws — WSO2 CVE-2026-5430 and Adobe Commerce CVE-2026-71362 — to its KEV catalog, patch deadline Sept 27.

Two unrelated critical bugs, both under active exploitation, both landed on the KEV list the same week — with a shared September 27 patch deadline for federal agencies.

Conceptual illustration showing a WSO2 icon and an Adobe Commerce icon both connecting to a central CISA Known Exploited Vulnerabilities catalog shield, with a September 27, 2026 deadline marker
Conceptual illustration of two unrelated vulnerabilities converging on the same CISA KEV deadline. Source: Generated by UnpanicTech.

On September 24, 2026, CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: one in WSO2's API management stack and one in Adobe Commerce and Magento [1]. Both additions were based on evidence of real-world exploitation, and both give Federal Civilian Executive Branch (FCEB) agencies until September 27, 2026, to apply fixes [1]. The two products have nothing to do with each other technically, but their KEV listings landed in the same news cycle, which is worth separating out clearly rather than treating as one story.

What CISA Added

The catalog update covers two CVEs:

CVE Product CVSS Type KEV Added
CVE-2026-5430 WSO2 API Control Plane, API Manager, Traffic Manager, Universal Gateway 9.8 Path traversal / unsafe file handling, per CISA's KEV listing[1] Sept 24, 2026
CVE-2026-71362 Adobe Commerce, Magento Open Source 9.1 Incorrect authorization (session/account context) Sept 24, 2026

A quick note on how CISA itself labeled these two entries: the KEV catalog record for CVE-2026-5430 is titled a "path traversal" issue in WSO2's products, and that's the framing The Hacker News used in its report, describing unrestricted file upload leading to remote code execution [1]. That framing is not the only one circulating, though — several independent vulnerability trackers and WSO2's own advisory numbering (WSO2-2026-5328) point to CVE-2026-5430 as a JWT signature-verification weakness (tracked under CWE-347) that lets an attacker forge an authentication token and bypass login entirely, rather than a classic directory-traversal bug. Both descriptions point to the same practical outcome: unauthenticated attackers gaining administrative-level access to affected WSO2 deployments. Where sources disagree on the precise mechanism, that disagreement is worth flagging honestly rather than picking one version and presenting it as beyond dispute.

The WSO2 Flaw

Flow diagram showing an unauthenticated attacker sending a forged JSON Web Token to a WSO2 gateway, the signature check failing to reject an unsupported algorithm, and the token being accepted for administrative access
Conceptual illustration of the authentication-bypass mechanism described in WSO2 advisory WSO2-2026-5328 and corroborating vulnerability research. Source: Generated by UnpanicTech.

Whichever exact mechanism ends up being the authoritative one, the practical story is straightforward. CVE-2026-5430 affects WSO2's API Control Plane, API Manager, Traffic Manager, and Universal Gateway — the components that sit in front of an organization's APIs and decide who gets to call them. An attacker who doesn't need valid credentials to get administrative access to that layer can, in principle, read, modify, or redirect API traffic, create new accounts, or pull data from anything the gateway fronts.

Security firm watchTowr said its honeypot network began picking up exploitation attempts against this flaw on September 13, 2026, more than a week before the KEV listing went live [2]. Cyber Daily reported that the vulnerability had first been disclosed back in July 2026, meaning attackers were still actively probing for it months after a patch existed — a pattern that shows up repeatedly with API management software, where upgrade cycles tend to lag behind the disclosure timeline [2].

The Adobe Commerce Flaw

Flow diagram showing an attacker session bypassing an authorization check to gain access to a different customer account's order history and profile data in Adobe Commerce
Conceptual illustration of the session/account-context issue described by Sansec for CVE-2026-71362. Source: Generated by UnpanicTech.

CVE-2026-71362 is a different kind of problem. It's an incorrect-authorization bug in Adobe Commerce and Magento that lets an attacker switch an active session over to a different customer's account context, without needing that customer's password. Dutch e-commerce security firm Sansec, which flagged exploitation attempts back in August 2026, put it plainly: the flaw lets attackers switch a customer session to another customer account, giving them access to that victim's account and private data [1].

Exploitation evidence here is thinner than for the WSO2 bug, and it's worth being precise about that rather than rounding up. Sansec detected and blocked attempts in August. Separately, threat-intelligence firm Previdian recorded a single IP address, geolocated to Australia, attempting to exploit the flaw against its honeypot sensors on September 10, 2026 [1]. As of the KEV addition, Adobe had not updated its own advisory to confirm exploitation status [1]. CISA's KEV listing is based on the agency's own evidence threshold, which doesn't require vendor confirmation — so the KEV entry and Adobe's advisory can be in different places on timing, and that gap is normal rather than a sign either source is wrong.

Why the KEV Listing Matters

Getting added to CISA's KEV catalog is a specific, narrow signal: it means CISA has evidence of active exploitation, not just a theoretical risk or a high CVSS score [1]. Binding Operational Directive 26-04 requires FCEB agencies to remediate KEV-listed vulnerabilities on a fixed schedule, with priority given to internet-exposed assets where a successful exploit hands over full control [3]. That's a narrower and stronger claim than "this is a serious bug" — it means someone is actually using it against real targets right now, not that it merely could be used that way.

For both of these CVEs, the September 27, 2026 deadline is a federal requirement, not a universal one. Private-sector organizations running WSO2 or Adobe Commerce aren't bound by CISA's directive, but the same evidence of active exploitation applies to them just as much as it does to a federal agency's network.

Mitigation

Four-step checklist graphic covering patching, log review, restricting exposure, and confirming remediation before the CISA deadline
Conceptual summary of the defensive steps discussed in this article. Source: Generated by UnpanicTech.

WSO2 has patches available for the affected product lines, and organizations running API Control Plane, API Manager, Traffic Manager, or Universal Gateway should check their specific deployed version against the vendor's current advisory rather than assuming an older patch already covers this. Adobe has likewise shipped fixes for Commerce and Magento Open Source. Beyond patching, defenders can reasonably:

  • Check authentication and session logs for unexpected token algorithms or unexplained account-context switches.
  • Limit direct internet exposure of gateway administration interfaces where that's operationally feasible.
  • Treat the September 27 date as a strong working deadline even outside the federal government, given the confirmed exploitation activity.

What's Still Unclear

Two things are worth stating honestly rather than glossing over. First, the exact technical description of CVE-2026-5430 — path traversal versus JWT signature bypass — is not fully settled across public sources at the time of writing, even though the practical risk (unauthenticated administrative access) is consistent either way. Second, the scope of real-world exploitation for CVE-2026-71362 is still limited to a handful of documented attempts; it's enough for CISA to list it as actively exploited, but it isn't evidence of a broad, ongoing campaign.

The Takeaway

Neither of these flaws needed to happen at the same time to matter on its own, but the coincidence is a useful reminder that KEV additions aren't ranked by fame or vendor size — they're driven by evidence of exploitation, full stop. If your organization runs WSO2's API management products or Adobe Commerce/Magento, this is a patch-now situation regardless of whether you answer to a federal directive.

Sources & References

  1. The Hacker News — "WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV," Ravie Lakshmanan, Sept 25, 2026
  2. Cyber Daily — "Update: WSO2 API Manager vulnerability officially added to CISA's KEV Catalog," David Hollingworth, Sept 25, 2026
  3. CISA — "CISA Adds Two Known Exploited Vulnerabilities to Catalog," Sept 24, 2026
  4. CISA — Known Exploited Vulnerabilities Catalog
NK

Naseem Khan (Technical Editor)

Cybersecurity Researcher & Technical Editor

UnpanicTech is supported by a dedicated team of cybersecurity specialists and writers. All research and articles are comprehensively reviewed and published by our Technical Editor, Naseem Khan, covering vulnerability analysis, defensive security, incident response, cloud security, and practical security engineering.

Technical Discussion & Feedback

Leave a Comment (Authenticated Users)