⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

September 25, 2026

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV Ravie LakshmananSep 25, 2026Vulnerability / Web Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below – CVE-2026-5430 (CVS score: 9.8) – A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remote code execution. CVE-2026-71362 (CVSS score: 9.1) – An incorrect authorization vulnerability in Adobe Commerce and Magento that could allow an attacker to leverage this vulnerability to gain elevated access…

CVEs: CVE-2026-5430, CVE-2026-71362