CISA Adds WSO2 and Adobe Commerce Bugs to Its Exploited List
Security / news
CISA Adds WSO2 and Adobe Commerce Bugs to Its Exploited List
The Sept. 24 additions carry a maximum CVSS score of 10.0 for a WSO2 authentication bypass and 9.1 for a Magento session flaw, and neither now gets the fixed deadline CISA used to hand out.
CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on Sept. 24: a maximum-severity, CVSS 10.0 authentication bypass affecting WSO2's API Manager and related products, and a CVSS 9.1 authorization flaw in Adobe Commerce and Magento Open Source that lets an attacker take over another customer's session without a password.
Security firm watchTowr said it has seen in-the-wild exploitation attempts against its honeypots for the WSO2 flaw, CVE-2026-5430, since at least Sept. 13, The Hacker News reported Sept. 24. Sansec said it detected and blocked exploitation attempts against the Adobe Commerce flaw, CVE-2026-71362, in August, and threat-intelligence firm Previdian logged a single attempt from an Australian IP address against its honeypot sensors on Sept. 10.
What each flaw actually lets an attacker do
WSO2's own advisory, published May 3, describes CVE-2026-5430 as a JWT algorithm-confusion bug: when a token's alg header names an algorithm the server does not support, WSO2's validation function fails open and accepts the token's claims without ever checking a signature. A forged token grants full administrative access to the API Manager management plane. The flaw affects API Manager 4.1.0 through 4.6.0, plus the API Control Plane, Traffic Manager and Universal Gateway products, all now patched at vendor-specific update levels.
CISA's own catalog entry describes a different bug entirely: it calls CVE-2026-5430 a "WSO2 Multiple Products Path Traversal Vulnerability" that "could allow for unrestricted file upload and lead to remote code execution." WSO2's advisory does not mention path traversal, file upload or remote code execution anywhere; it describes a JWT algorithm-confusion authentication bypass that reaches admin access through a forged token, not a planted file. The federal catalog and the vendor's own writeup of the same CVE number describe two different vulnerabilities.
CVE-2026-71362 is more straightforward: an incorrect-authorization flaw, tracked under CWE-863, that lets an unauthenticated remote attacker "escalate privileges and obtain elevated access to the application without any user interaction," citing Adobe's own security bulletin APSB26-92. It affects Adobe Commerce 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.6 through 2.4.9, on any build predating Adobe's August 2026 patch releases.
| CVE | Product | CVSS | Exploitation observed since |
|---|---|---|---|
| CVE-2026-5430 | WSO2 API Manager and related products | 10.0 (9.8 single-tenant) | Sept. 13, 2026 (watchTowr) |
| CVE-2026-71362 | Adobe Commerce, Magento Open Source | 9.1 | August 2026 (Sansec) |
A remediation clock that no longer reads the same for every bug
CISA's Sept. 24 alert gives no fixed calendar date for federal remediation, unlike past additions to the same catalog, because BOD 26-04, the directive that replaced the old BOD 22-01 in 2026, sets timelines per asset based on exposure, exploitation status and technical impact rather than a uniform 14 or 21 days. The directive's own text puts the shortest tier at three days, and The Hacker News reported federal agencies were advised to apply fixes for both flaws by Sept. 27, exactly that three-day floor from the Sept. 24 addition.
A public proof-of-concept for the Adobe Commerce flaw is already circulating on GitHub, according to The Hacker News's reporting, the same platform that spent 24 days on a different malware complaint this month before acting within minutes of a Hacker News post. Neither watchTowr, Sansec nor Previdian has named the party behind the scanning traffic it observed, and CISA's alert does not either.
The pace of discovery matches a broader pattern this week, in which automated scanning for known flaws runs continuously and often surfaces before any human researcher goes looking. Transluce traced a separate wave of scanning and exploitation attempts back to OpenAI agents using a free URL-scanning tool, running from March to September before becoming public. Both WSO2 and Adobe have shipped fixes; the open question for each is how many unpatched instances remain reachable from the internet, a number neither vendor has published.
Sources
More in Security
- 01CISA Gives Agencies 3 Days to Patch an Exploited SharePoint BugMicrosoft rated the flaw a low-risk spoofing issue for 16 days after patching it, and a honeypot logged the first attack four weeks after the correction upgraded it to an 8.8.
- 02CISA Adds a Fourth MikroTrick Bug to Its Exploited ListCVE-2026-67279 joins two other bugs from the same six-flaw MikroTik batch already on CISA's list, but Bishop Fox says it, not the pair flagged in September, is the one that actually opens the door.
- 03OpenClaw's New Scanners Agree on Just 0.69% of Risky SkillsFour audits since February have counted between 341 and 1,467 malicious or flawed skills on ClawHub, and NVIDIA's scanner disagrees with the other two on all but 468 of 67,453 skills checked.
- 04CISA Lists 14 Botslab Dashcam Flaws With No Fix in SightThe worst of the bugs lets a network attacker push firmware with no cryptographic signature onto the device, and Botslab has not told CISA whether it plans to fix any of the 14.