WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
- ID
- 28482
- Status
- summarized
- Published
- 25 Sep 2026, 12:46 PM
- Fetched
- 25 Sep 2026, 4:42 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.0
- Created
- 25 Sep 2026, 4:42 PM
- Tags
- Audience
- developerssaas_founders
What happened
CISA added two critical flaws to its Known Exploited Vulnerabilities catalog on Sept 25, 2026: CVE-2026-5430 (CVSS 9.8), a path traversal in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that allows unrestricted file upload leading to remote code execution, and CVE-2026-71362 (CVSS 9.1), an incorrect authorization flaw in Adobe Commerce and Magento that lets an attacker switch a customer session to another customer's account without user interaction. watchTowr reported in-the-wild exploitation attempts against its honeypots since at least Sept 13, 2026; Sansec said it detected and blocked exploitation attempts in August 2026; and Previdian logged an attempt from a single Australian IP on Sept 10, 2026. Federal Civilian Executive Branch agencies must apply fixes by Sept 27, 2026, and Adobe has not updated its advisory to confirm exploitation.
Why it matters
If you run Adobe Commerce/Magento storefronts, the flaw leaks customer account and private data with no user interaction, so patching is not optional and customer-session logs are worth checking for account-switching anomalies. If you run WSO2 API Manager, Traffic Manager, Universal Gateway or API Control Plane, the file-upload-to-RCE path has been probed in honeypots since Sept 13 — inventory those gateway versions today rather than after a breach. Everyone else can skip this one; it does not touch AI, agent, or general dev tooling.
Discussion angle
CISA gave federal agencies until Sept 27 — roughly two days after publication — for a 9.8 RCE that honeypots had already been hit with since Sept 13, while Adobe still has not confirmed exploitation of the 9.1 Commerce/Magento bug. Worth debating: should vendor advisories that lag behind third-party honeypot evidence change how fast your team patches?