Government Advisory

CISA Flags Actively Exploited Flaws in WSO2 and Adobe Commerce/Magento

CISA · 24 Sept 2026
Key Takeaway If your business runs Adobe Commerce, Magento, or WSO2 software, check for updates immediately, as these flaws are already being exploited by attackers.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited by attackers. The first, CVE-2026-5430, is a path traversal vulnerability affecting multiple WSO2 products. The second, CVE-2026-71362, is an incorrect authorization vulnerability in Adobe Commerce and Magento, popular e-commerce platforms used by many online retailers.

While CISA's binding directive to patch these flaws quickly only applies to US federal agencies, the agency strongly encourages all organisations to treat KEV Catalog entries as high priority. Vulnerabilities that are actively exploited in the wild pose a much greater risk than unexploited ones, since attackers already have working methods to abuse them, often to gain full control of affected systems.

Australian businesses running Adobe Commerce, Magento, or WSO2 products, particularly online stores and web-facing applications, should check whether they are affected and apply vendor patches as soon as possible.

CISA KEV Catalog Adobe Commerce Magento WSO2 vulnerability management

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.