importantSYS.SOURCE: The Hacker News• 2026-09-25T10:16:34+05:30
Critical Vulnerabilities in WSO2 and Adobe Commerce Exploited in Active Attacks, Added to CISA KEV
Two critical vulnerabilities in WSO2 and Adobe Commerce were actively exploited and added to CISA's KEV catalog, urging immediate patching for affected organizations. The flaws enable remote code execution and unauthorized access, impacting sectors like banking and government.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerabilities are listed below -
CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,
*** END OF TRANSMISSION ***