The U.S. Cybersecurity and Infrastructure Security Agency has added two enterprise-software vulnerabilities to its Known Exploited Vulnerabilities catalog. The additions cover CVE-2026-5430 in WSO2 products and CVE-2026-71362 in Adobe Commerce and Magento.
Two different attack paths
The WSO2 issue is a path-traversal weakness that can enable unrestricted file upload and potentially remote code execution in affected API-management components. Security researchers reported exploitation attempts before the catalog update. The Adobe Commerce issue is an authorization flaw that can allow an attacker to reach another customer’s account context and sensitive information under vulnerable conditions.
KEV inclusion means CISA has evidence that the vulnerabilities are being exploited, not merely that public proof-of-concept material exists. Federal civilian agencies received a remediation deadline, while private organizations can use the catalog as a prioritization signal alongside asset exposure, business impact and compensating controls.
Prioritization for defenders
Teams should inventory affected WSO2, Adobe Commerce and Magento deployments, compare versions against vendor advisories, apply fixes, and inspect logs for file-upload anomalies, forged tokens or unusual account switching. Internet-facing systems and identity-connected APIs deserve immediate attention. SectechMedia follows similar operational risk in its cyber-physical security channel.

Leave a Reply