Critical WSO2 and Adobe Commerce Flaws Added to CISA's KEV List
CISA adds actively exploited vulnerabilities in WSO2 and Adobe Commerce to its Known Exploited Vulnerabilities catalog. Organizations are urged to patch immediately to avoid potential breaches.
TL;DR
- CISA adds two critical vulnerabilities to its KEV catalog: CVE-2026-5430 (WSO2) and a flaw in Adobe Commerce/Magento.
- Both flaws are being actively exploited in the wild, increasing risk for unpatched systems.
- CVE-2026-5430 is a path traversal bug in WSO2 API Control Plane with a CVSS score of 9.8.
- Adobe Commerce and Magento users should review their environments for signs of compromise.
- Immediate patching and monitoring are recommended for affected platforms.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog with two high-severity flaws affecting WSO2 and Adobe Commerce platforms. These vulnerabilities are already being exploited by threat actors, making prompt remediation essential for organizations using these technologies.
The inclusion in the KEV catalog signals that federal agencies and private sector entities alike must prioritize mitigation efforts. Both flaws enable attackers to potentially gain unauthorized access or execute malicious actions, underscoring the urgency for system administrators to apply available patches and assess their environments for indicators of compromise.
WSO2 Path Traversal Vulnerability
- CVE-2026-5430 affects WSO2 API Control Plane and carries a critical CVSS score of 9.8.
- The flaw allows attackers to traverse directories and access sensitive files on the server.
- Active exploitation has been observed, suggesting real-world attacks are underway.
- Organizations using WSO2 products should immediately apply vendor-released patches.
Adobe Commerce and Magento Flaw
- A critical vulnerability in Adobe Commerce and Magento has also been added to the KEV list.
- This flaw is being exploited alongside CVE-2026-5430 in coordinated campaigns.
- Details of the specific exploit vector remain limited but involve remote code execution risks.
- Merchants and enterprises running Adobe Commerce or Magento should audit logs and update systems promptly.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.