CISA KEV: WSO2 and Adobe Commerce Flaws Exploited
CISA added CVE-2026-5430 (WSO2, CVSS 10.0) and CVE-2026-71362 (Adobe Commerce, CVSS 9.1) to KEV on September 24. Federal patch deadline: September 27.

Two exploited flaws landed on CISA’s Known Exploited Vulnerabilities catalog Thursday: a path traversal bug in WSO2’s API stack and an authorization flaw in Adobe Commerce and Magento Open Source. Federal civilian agencies have until September 27 to patch both. If you run either product, that deadline is relevant regardless of your sector.
CVE-2026-5430: WSO2, path traversal, CVSS 10.0
This flaw affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. An unauthenticated attacker can exploit a path traversal to upload arbitrary files and reach remote code execution. CISA’s catalog entry places the start of active exploitation at September 13.
WSO2 first appeared on this site’s radar September 17, when exploitation was already confirmed in enterprise environments: WSO2 CVSS 10 JWT Bypass Exploited in the Wild. The KEV listing formalizes what that reporting already showed.
Apply WSO2’s security patch for your specific product version. The NVD record for CVE-2026-5430 links to the full advisory chain. If patching today is not possible, restrict external network access to WSO2 management interfaces and block the affected upload paths at the perimeter until the fix is in place.
CVE-2026-71362: Adobe Commerce / Magento, CVSS 9.1
Adobe Commerce and Magento Open Source carry an incorrect authorization flaw that lets an attacker escalate privileges and access resources without credentials or user interaction. In active exploitation, attackers have used it to switch customer sessions to other customers’ accounts, reaching order history and stored account data.
Exploitation was running as early as August 2026, when we covered the initial attack wave on August 12. Adobe’s advisory did not confirm exploitation status at the time it published; CISA’s KEV addition is based on independent evidence.
Patch now. The NVD record for CVE-2026-71362 has the full version range. Adobe’s security patch portal carries the fix for each affected version. There is no workaround: patching is the only remediation.
Patch priority
Both entries carry a BOD 26-04 deadline of September 27 for federal civilian agencies. That is two days.
For everyone else: KEV status means CISA confirmed active exploitation, not flagged a theoretical risk. Patch WSO2 first. The CVSS 10.0 score and the path to unauthenticated remote code execution put it ahead. Get Adobe Commerce right after.
This week’s KEV additions also included Zyxel and Veeam flaws added September 22 and TeamCity added to the ransomware-exploited list on September 24. Busy patch week.
- [ CRITICAL ]CVE-2026-5430WSO2 Multiple Products Path Traversal to RCE
- [ CRITICAL ]CVE-2026-71362Incorrect Authorization in Adobe Commerce and Magento Open Source
Found this useful? Share it.


