U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
September 25, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
  • CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability

The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products caused by improper verification of JWT signatures, allowing an attacker to use an unsupported signing algorithm to gain unauthorized access and potentially take over accounts.

The second flaw added to the catalog, tracked as CVE-2026-71362 (CVSS score 9.1), is an incorrect authorization vulnerability in Adobe Commerce that can allow an unauthenticated attacker to escalate privileges and gain access to sensitive resources without user interaction. In August 2026, hackers began targeting CVE-2026-71362 shortly after its public disclosure. The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data.

Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory. The flaw affects Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches. Adobe released an isolated fix and urged users to patch.

“Adobe has released APSB26-92 as isolated patch files. The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9.1. Sansec Shield already blocks exploitation attempts.” reads the advisory published by Sansec. “Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data.”

Sansec pointed out that an attacker can exploit the flaw without an existing account, administrator privileges, or user interaction.

Adobe fixed how Magento handles customer identity in account sessions. The remaining flaws include stored cross-site scripting and authorization issues.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaws by September 27, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.