CISA Flags Actively Exploited Flaws in WSO2 and Adobe Commerce/Magento
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited by attackers. The first, CVE-2026-5430, is a path traversal vulnerability affecting multiple WSO2 products. The second, CVE-2026-71362, is an incorrect authorization vulnerability in Adobe Commerce and Magento, popular e-commerce platforms used by many online retailers.
While CISA's binding directive to patch these flaws quickly only applies to US federal agencies, the agency strongly encourages all organisations to treat KEV Catalog entries as high priority. Vulnerabilities that are actively exploited in the wild pose a much greater risk than unexploited ones, since attackers already have working methods to abuse them, often to gain full control of affected systems.
Australian businesses running Adobe Commerce, Magento, or WSO2 products, particularly online stores and web-facing applications, should check whether they are affected and apply vendor patches as soon as possible.