CISA Warns of Active Exploitation of WSO2 and Adobe Commerce Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities, CVE-2026-5430 affecting WSO2 and CVE-2026-71362 affecting Adobe Commerce and Magento, to its Known Exploited Vulnerabilities (KEV) catalog. Both flaws have been targeted in real-world attacks, with security researchers observing exploitation attempts against honeypot systems as far back as September 2026.
The Adobe Commerce flaw is particularly concerning for online retailers, as it allows attackers to hijack a customer's session and switch it to another account. This gives attackers unauthorised access to private customer data and account controls. Security firm Sansec detected and blocked exploitation attempts targeting this vulnerability in August 2026, and separate telemetry recorded at least one attempted exploit originating from an Australian IP address in September.
CISA has directed U.S. federal agencies to patch both vulnerabilities by September 27, 2026, but the risk extends well beyond government networks. Any business running WSO2 products or Adobe Commerce and Magento e-commerce platforms should treat these as urgent patching priorities, given confirmed exploitation in the wild.