CISA says attackers are actively exploiting critical flaws in WSO2 and Adobe Commerce, along with additional issues in Microsoft SharePoint and Mikrotik RouterOS. Federal agencies must patch the critical KEV entries by September 27, while SharePoint and RouterOS fixes are due by September 28. #WSO2 #AdobeCommerce #MicrosoftSharePoint #MikrotikRouterOS #CVE-2026-5430 #CVE-2026-71362 #CVE-2026-65660 #CVE-2026-67279
Keypoints
- CISA added CVE-2026-5430 in WSO2 products to its KEV catalog.
- CVE-2026-5430 can let attackers compromise administrative accounts and gain full control.
- CISA also listed CVE-2026-71362 affecting Adobe Commerce and Magento.
- Hackers are exploiting a Microsoft SharePoint code injection flaw and a Mikrotik RouterOS workflow bypass.
- Federal agencies must remediate the critical KEV flaws by September 27 and the other two by September 28.