CISA has added two critical vulnerabilities, CVE-2026-5430 in WSO2 products and CVE-2026-71362 in Adobe Commerce and Magento, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaws can enable remote code execution or unauthorized access to sensitive customer data, and FCEB agencies must patch them by September 27, 2026. #CVE-2026-5430 #CVE-2026-71362 #WSO2 #AdobeCommerce #Magento
Keypoints
- CISA added two actively exploited flaws to its KEV catalog.
- CVE-2026-5430 affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway.
- The WSO2 flaw could allow unrestricted file upload and remote code execution.
- CVE-2026-71362 affects Adobe Commerce and Magento and may expose sensitive customer resources.
- FCEB agencies must apply fixes for both vulnerabilities by September 27, 2026.
Read More: https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html