The US Cybersecurity and Infrastructure Security Agency ( CISA ) has added two critical vulnerabilities in WSO2 and Adobe Commerce to its Known Exploited Vulnerabilities (KEV) list , confirming that both vulnerabilities are actively being exploited by malicious actors. These vulnerabilities have extremely high CVSS scores, putting organizations worldwide, including government agencies and e-commerce businesses, at risk. Authorities are urging immediate implementation of available patches.

The inclusion of these two vulnerabilities in CISA ’s KEV catalog is no coincidence. This catalog is essentially a “blacklist” of known and actively exploited vulnerabilities, which is used as a priority guide for security teams. Every time a vulnerability is included in it, it means that there is compelling evidence of actual exploitation — it is not just a theoretical threat. This makes immediate response imperative for any organization using the affected products.
The context of the attacks is particularly worrying: on the one hand, the vulnerability in WSO2 allows remote code execution (RCE) via uncontrolled file upload, while on the other hand, the weakness in Adobe Commerce and Magento allows attackers to gain access to customer accounts and sensitive data without any user interaction. Both scenarios represent serious threats to data integrity and confidentiality.
See also: CVE-2026-5430: Critical WSO2 API Manager vulnerability actively exploited
WSO2: The CVE-2026-5430 vulnerability and the risk of Remote Code Execution
The vulnerability CVE-2026-5430 has received a CVSS score of 9.8 . It is a path traversal vulnerability that affects multiple WSO2 products , specifically the API Control Plane , API Manager , Traffic Manager , and Universal Gateway . Its exploitation allows an attacker to upload files without any restrictions, ultimately leading to remote code execution — that is, the execution of arbitrary code on the target server.
Cybersecurity firm watchTowr reported that it had detected attempts to exploit CVE-2026-5430 in honeypots since at least September 13, 2026 — about a week before CISA officially added the vulnerability to the KEV catalog. This means that attackers had already begun actively exploiting the vulnerability before the authorities even issued an official warning. The use of honeypots by security researchers is a critical tool for early detection of such attacks.
WSO2 products are widely used by enterprises and government organizations to manage APIs and integrate services. The RCE capability in such systems can lead to a complete infrastructure compromise, data theft, installation malware , or even ransomware . The risk is particularly high for organizations that expose WSO2 systems directly to the internet without adequate protection.

Adobe Commerce and Magento: The Impact on E-Commerce
The second vulnerability, CVE-2026-71362, affects Adobe Commerce and Magento — two of the most popular e-commerce platforms in the world. With a CVSS score of 9.1, the vulnerability is categorized as an “incorrect authorization” and allows an attacker to gain elevated access to sensitive resources without any interaction with the victim user. This means that the attack can be carried out completely silently, without having to trick a user.
Dutch e-commerce security firm Sansec reported back in August 2026 that it had detected and blocked attempts to exploit the vulnerability. According to Sansec, “the vulnerability allows attackers to switch from one customer session to another customer account,” giving them access to the victim’s data and private information. In practice, this means that a malicious user could “impersonate” other customers, view their orders, payment details, and other sensitive data.
See also: Adobe fixes zero-day in Adobe Commerce & Magento
Additionally, Previdian reported that its telemetry identified a single IP address from Australia that attempted to exploit the vulnerability by targeting honeypot on September 10, 2026.It is worth noting that Adobe has yet to officially update its advisory to confirm the exploit status, which raises concerns about the company's speed of response.
Magento and Adobe Commerce are used by millions of online stores worldwide, including many Greek businesses. A successful exploitation of CVE -2026-71362 could lead to a massive leak of customer data, a breach of payment credentials, and serious legal consequences for businesses that have not implemented the necessary security updates.

CISA deadline and obligations for WSO2 and Adobe Commerce
According to The Hacker News, CISA has set a deadline for implementing fixes for both vulnerabilities as September 27, 2026.This guidance is primarily aimed at the Federal Civilian Executive Branch (FCEB) in the US, but it is a strong recommendation for any organization worldwide that uses the affected products. Failure to comply by the deadline could have serious consequences for network security.
The inclusion of vulnerabilities in the KEV catalog has proven to be one of the most effective tools for raising awareness and accelerating the response of organizations. Statistically, vulnerabilities included in the KEV have a significantly higher exploitation rate than average, which underlines the seriousness of the situation. Organizations that remain inactive in the face of such warnings are taking a huge risk.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: StyleSmuggler: Active zero-day threatens Magento and Adobe Commerce
Practical security tips for WSO2 and Adobe Commerce
For Adobe Commerce and Magento users , immediately updating to the latest version that includes the fix for CVE-2026-71362 is a top priority. Additionally, it is recommended to monitor session logs for abnormal account transitions, enable alerts for suspicious activity, and use a Web Application Firewall (WAF) for additional protection. E-commerce businesses should also notify their customers if a data breach is suspected.
For system administrators using WSO2 API Manager, API Control Plane, Traffic Manager , or Universal Gateway, it is imperative that they apply the available patches immediately. They are also advised to review logs for suspicious activity related to file uploads, as well as check for traces of exploitation that may have already occurred.
