zero-day • The Hacker News

CISA lisää aktiivisesti hyödynnetyt WSO2- ja Adobe Commerce -haavoittuvuudet KEV-luetteloon

CISA lisäsi CVE-2026-5430 (WSO2) ja CVE-2026-71362 (Adobe Commerce) KEV-luetteloon. Määräaika 27.9.

CISA lisää aktiivisesti hyödynnetyt WSO2- ja Adobe Commerce -haavoittuvuudet KEV-luetteloon

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on September 24, 2026, added two critical flaws to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-5430 (CVSS 9.8) is a path traversal in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that can enable unrestricted file upload and RCE. CVE-2026-71362 (CVSS 9.1) is an incorrect authorization bug in Adobe Commerce and Magento that lets attackers gain elevated access to sensitive resources without user interaction. Federal civilian agencies must remediate both by September 27, 2026.

For WSO2 the timeline is especially severe. watchTowr reported capturing forged JWT (JSON Web Token) traffic against its honeypots since at least September 13 — more than a week before CISA's formal KEV listing. Principal threat intelligence specialist Yordan Ganchev stressed that WSO2 is not niche technology: nearly 1,000 customers across banking, government, telecommunications and logistics rely on it. By the time a flaw reaches KEV, attackers often already had days or weeks to act. Path traversal plus file upload can turn an internet-facing gateway into a backdoor inside the API fabric that stitches critical systems together.

The Adobe Commerce/Magento flaw hits e-commerce harder. Dutch firm Sansec blocked exploitation attempts in August 2026 and described how attackers can switch a customer session to another account — exposing private customer data. Previdian honeypot telemetry recorded a single Australian IP attempting exploitation on September 10. Adobe had not yet updated its advisory to explicitly confirm in-the-wild status at reporting time, but CISA's KEV decision means the federal evidence bar for action is considered met.

Nordic banks, municipalities and online retailers share the same imperative: inventory WSO2 components and Magento/Adobe Commerce stores, apply vendor patches, and shrink internet exposure of admin and API surfaces. A compromised API gateway can unlock lateral movement far beyond a storefront; a Magento session swap can leak personal data and enable fraud. The September 27 deadline is short — treat both CVEs as urgent.

Concrete steps for IT and security leaders

1. Inventory WSO2 API Manager/Gateway and Adobe Commerce/Magento in production and staging. 2. Apply WSO2 security updates or open-source pull requests per advisory; follow Adobe's security update guide. 3. Isolate admin and management APIs behind VPN or zero-trust access. 4. Review logs for unusual JWT signatures, path-traversal strings and session-switching since mid-September. 5. For e-commerce: audit customer accounts for unexplained sessions and strengthen customer authentication where possible.

Evidence Rail

  • Confirmed: CISA KEV listing; watchTowr honeypot evidence for WSO2 since September 13; Sansec blocks against the Adobe flaw.
  • Reported: Previdian telemetry (AU IP September 10); ~1,000-organisation WSO2 customer base.
  • Unconfirmed: Whether Adobe has updated its advisory with explicit wild confirmation at time of publication.

In Brief

  • WSO2 path traversal (CVE-2026-5430) and Adobe Commerce authorization flaw (CVE-2026-71362) are actively exploited and now in CISA KEV.
  • WSO2 exploitation was observed at least a week before the KEV listing.
  • Federal patch deadline is September 27 — Nordic organisations should move just as fast.

Lähteet ja viitteet

← Kaikki uutiset Työkalut