CISA added CVE-2026-5430 affecting WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway, and CVE-2026-71362 affecting Adobe Commerce and Magento, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. The WSO2 flaw is a critical path-traversal issue that can permit unrestricted file uploads to unintended locations and potentially lead to remote code execution; exploitation has been observed since at least September 13. The Adobe/Magento authorization flaw enables unauthenticated customer-session switching, exposing private customer data and potentially allowing account hijacking or privilege escalation.
U.S. federal civilian executive-branch agencies must remediate both vulnerabilities by September 27, 2026, under CISA’s Binding Operational Directive process. Organizations operating affected WSO2 systems should inventory internet-facing deployments, apply vendor mitigations or remove unmitigated instances from service, and perform forensic triage for anomalous file writes, accounts, processes, logs, and outbound connections. Adobe Commerce and Magento administrators should apply Adobe’s available patches and review customer-session activity for signs of unauthorized access.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
CIRT.cm issued alert CIRT-AL-2026-09-26 warning Cameroonian organizations about five critical vulnerabilities, including Arista CVE-2026-93952, which it stated was actively exploited and listed in CISA's Known Exploited Vulnerabilities catalog. The alert also reiterated active-exploitation warnings for the previously recorded WSO2 and Adobe Commerce flaws.
CISA added Microsoft SharePoint code-injection vulnerability CVE-2026-65660 and MikroTik RouterOS vulnerability CVE-2026-67279 to its Known Exploited Vulnerabilities catalog, citing active exploitation. Microsoft reported reliable attack evidence against SharePoint and CISA flagged it for forensic triage; MikroTik had released fixes for supported RouterOS branches.
watchTowr observed in-the-wild attempts to exploit the WSO2 path-traversal vulnerability CVE-2026-5430 against its honeypots. The flaw can allow unrestricted file uploads and potentially remote code execution.
Previdian telemetry recorded an attempt to exploit CVE-2026-71362 against its honeypot sensors. The activity originated from a single IP address in Australia.
CISA added actively exploited CVE-2026-5430 in WSO2 products and CVE-2026-71362 in Adobe Commerce and Magento to its Known Exploited Vulnerabilities catalog. CISA directed U.S. federal civilian executive-branch agencies to remediate both vulnerabilities by September 27, 2026.
Sansec detected and blocked exploitation attempts against CVE-2026-71362. The flaw can enable an attacker to switch a customer session to another account and access private customer data.
Adobe publicly disclosed the Adobe Commerce and Magento authorization flaw CVE-2026-71362 and released isolated patch files under advisory APSB26-92, which addressed seven vulnerabilities including the customer-account-takeover issue.
WSO2 released fixes for API Control Plane, API Manager, Traffic Manager, and Universal Gateway before exploitation of CVE-2026-5430 was confirmed. The JWT signature-verification flaw allows unauthenticated attackers to forge administrator tokens and bypass authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
12 references tracked. Mallory keeps watching after this page renders.
boho.or.kr
Open sourcethecyberthrone.in
Open sourcegov.br
Open sourcecirt.cm
Open sourcethehackernews.com
Open sourcelabs.beazley.security
Open sourcecve.org
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.