CISA Adds Exploited WSO2 and Adobe Commerce Flaws to KEV Catalog

Security camera undergoing privacy-mask persistence and configuration-drift testing

The U.S. Cybersecurity and Infrastructure Security Agency has added two enterprise-software vulnerabilities to its Known Exploited Vulnerabilities catalog. The additions cover CVE-2026-5430 in WSO2 products and CVE-2026-71362 in Adobe Commerce and Magento.

Two different attack paths

The WSO2 issue is a path-traversal weakness that can enable unrestricted file upload and potentially remote code execution in affected API-management components. Security researchers reported exploitation attempts before the catalog update. The Adobe Commerce issue is an authorization flaw that can allow an attacker to reach another customer’s account context and sensitive information under vulnerable conditions.

KEV inclusion means CISA has evidence that the vulnerabilities are being exploited, not merely that public proof-of-concept material exists. Federal civilian agencies received a remediation deadline, while private organizations can use the catalog as a prioritization signal alongside asset exposure, business impact and compensating controls.

Prioritization for defenders

Teams should inventory affected WSO2, Adobe Commerce and Magento deployments, compare versions against vendor advisories, apply fixes, and inspect logs for file-upload anomalies, forged tokens or unusual account switching. Internet-facing systems and identity-connected APIs deserve immediate attention. SectechMedia follows similar operational risk in its cyber-physical security channel.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *