DKDKCISSPSearch
Vulnerabilities

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation.

DKCISSP News DeskThe Hacker News29 Sept 2026, 4:25 pm
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation.

The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026.

In a statement shared with The Hacker News, a WSO2 spokesperson said the company alerted customers and provided the necessary security updates on April 6, 2026, and released a public advisory on May 3, 2026.

Adobe has yet to update its advisory to confirm exploitation status.

Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics.

Organizations in these sectors can't afford to wait for exploitation to be formally confirmed.

By the time a vulnerability reaches the KEV catalog, attackers already have days, or, in this instance, weeks, to act." As for CVE-2026-71362 , Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw.

It was exploitable, and attackers were already acting on it.

Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats.

(The story was updated after publication on September 29, 2026, to include a response from WSO2.)

What happened

Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation.

The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026.

What changed

In a statement shared with The Hacker News, a WSO2 spokesperson said the company alerted customers and provided the necessary security updates on April 6, 2026, and released a public advisory on May 3, 2026.

Adobe has yet to update its advisory to confirm exploitation status.

Who is affected

Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics.

Organizations in these sectors can't afford to wait for exploitation to be formally confirmed.

Technical details

By the time a vulnerability reaches the KEV catalog, attackers already have days, or, in this instance, weeks, to act." As for CVE-2026-71362 , Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw.

It was exploitable, and attackers were already acting on it.

Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats.

Response

(The story was updated after publication on September 29, 2026, to include a response from WSO2.)

Attribution

The Hacker News: Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmFortinet warns of critical FortiMail flaw exploited in zero-day attacksBleepingComputer · 2 Oct 2026, 4:12 amKiteworks patches max severity code injection vulnerabilityBleepingComputer · 1 Oct 2026, 7:21 pm