WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation.

Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation.
The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026.
In a statement shared with The Hacker News, a WSO2 spokesperson said the company alerted customers and provided the necessary security updates on April 6, 2026, and released a public advisory on May 3, 2026.
Adobe has yet to update its advisory to confirm exploitation status.
Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics.
Organizations in these sectors can't afford to wait for exploitation to be formally confirmed.
By the time a vulnerability reaches the KEV catalog, attackers already have days, or, in this instance, weeks, to act." As for CVE-2026-71362 , Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw.
It was exploitable, and attackers were already acting on it.
Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats.
(The story was updated after publication on September 29, 2026, to include a response from WSO2.)
What happened
Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation.
The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026.
What changed
In a statement shared with The Hacker News, a WSO2 spokesperson said the company alerted customers and provided the necessary security updates on April 6, 2026, and released a public advisory on May 3, 2026.
Adobe has yet to update its advisory to confirm exploitation status.
Who is affected
Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics.
Organizations in these sectors can't afford to wait for exploitation to be formally confirmed.
Technical details
By the time a vulnerability reaches the KEV catalog, attackers already have days, or, in this instance, weeks, to act." As for CVE-2026-71362 , Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw.
It was exploitable, and attackers were already acting on it.
Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats.
Response
(The story was updated after publication on September 29, 2026, to include a response from WSO2.)
Attribution
The Hacker News: Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation.
What to watch next
Watch for new exploitation reports and updated indicators of compromise.
Watch for updated vendor guidance and fixed-version details.