AI Weekly Malaysia

Back to items Summaries

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

ID
28482
Status
summarized
Published
25 Sep 2026, 12:46 PM
Fetched
25 Sep 2026, 4:42 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.0
Created
25 Sep 2026, 4:42 PM
Tags
Audience
developerssaas_founders

What happened

CISA added two critical flaws to its Known Exploited Vulnerabilities catalog on Sept 25, 2026: CVE-2026-5430 (CVSS 9.8), a path traversal in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that allows unrestricted file upload leading to remote code execution, and CVE-2026-71362 (CVSS 9.1), an incorrect authorization flaw in Adobe Commerce and Magento that lets an attacker switch a customer session to another customer's account without user interaction. watchTowr reported in-the-wild exploitation attempts against its honeypots since at least Sept 13, 2026; Sansec said it detected and blocked exploitation attempts in August 2026; and Previdian logged an attempt from a single Australian IP on Sept 10, 2026. Federal Civilian Executive Branch agencies must apply fixes by Sept 27, 2026, and Adobe has not updated its advisory to confirm exploitation.

Why it matters

If you run Adobe Commerce/Magento storefronts, the flaw leaks customer account and private data with no user interaction, so patching is not optional and customer-session logs are worth checking for account-switching anomalies. If you run WSO2 API Manager, Traffic Manager, Universal Gateway or API Control Plane, the file-upload-to-RCE path has been probed in honeypots since Sept 13 — inventory those gateway versions today rather than after a breach. Everyone else can skip this one; it does not touch AI, agent, or general dev tooling.

Discussion angle

CISA gave federal agencies until Sept 27 — roughly two days after publication — for a 9.8 RCE that honeypots had already been hit with since Sept 13, while Adobe still has not confirmed exploitation of the 9.1 Commerce/Magento bug. Worth debating: should vendor advisories that lag behind third-party honeypot evidence change how fast your team patches?

Top