Mastodon Mastodon Mastodon Mastodon

CISA added WSO2 and Adobe Commerce vulnerabilities to the Known Exploited Vulnerabilities catalog — what is known and what raises questions

Photo of author

CyberSecureFox Editorial Team

Published:

On September 24, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-5430 in WSO2 products and CVE-2026-71362 in Adobe Commerce and Magento Open Source. Inclusion in KEV means that CISA has evidence of active exploitation, and U.S. Federal Civilian Executive Branch (FCEB) agencies are required to remediate both vulnerabilities by September 27, 2026. However, when analyzing both CVEs, significant discrepancies emerge between sources — both in the technical description of the vulnerabilities and in the assessment of their exploitation status.

CVE-2026-71362: incorrect authorization in Adobe Commerce and Magento

The CVE-2026-71362 vulnerability is an authorization flaw (CWE-863, Incorrect Authorization) with a CVSS score of 9.1 according to Adobe. According to the APSB26-92 security advisory, the vulnerability allows an attacker, without authentication and without user interaction, to gain elevated access to confidential resources. The attack vector is network-based and the exploitation complexity is low (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Affected versions of Adobe Commerce: 2.4.9-2026-jul and earlier, 2.4.8-2026-jul and earlier, 2.4.7-2026-jul and earlier, 2.4.6-2026-jul and earlier, 2.4.5-2026-jul and earlier, 2.4.4-2026-jul and earlier. For Magento Open Source: 2.4.9-2026-jul and earlier, 2.4.8-2026-jul and earlier, 2.4.7-2026-jul and earlier, 2.4.6-2026-jul and earlier. The fix is delivered through the August 2026 updates as well as separate patches — details are available in Adobe’s patch installation guide.

A public GitHub repository provides a reproducible lab environment demonstrating the exploitation mechanism: an attacker can swap out a client session by switching it to another user’s account, which leads to account takeover and access to the victim’s personal data. The presence of a public PoC significantly lowers the barrier to entry for potential attackers.

Contradiction in exploitation status

This is where an important discrepancy arises. CISA has included CVE-2026-71362 in the KEV catalog, which implies evidence of exploitation. However, in the APSB26-92 advisory dated August 11, 2026, Adobe explicitly states: “Adobe is not aware of any exploits in the wild for any of the issues addressed in these updates” — the company had no information about exploitation at the time of publication. It is possible that the situation changed between August and September, but Adobe had not updated its advisory at the time of this analysis to confirm exploitation. This means that the “actively exploited” status is based on CISA’s data rather than vendor confirmation.

We have already written about critical vulnerabilities in Adobe products, including CVE-2026-71362 in the context of the APSB26-92 advisory. Its current addition to KEV raises the priority of this vulnerability for all organizations using Adobe Commerce or Magento.

CVE-2026-5430: unresolved discrepancies in the description of the WSO2 vulnerability

The situation with CVE-2026-5430 is more complex. The original news report describes it as a path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway products, allowing arbitrary file uploads and remote code execution. However, the entry in the GitHub Advisory Database (GHSA-j7vh-5w8q-4m4x) describes a completely different issue: improper verification of cryptographic signatures in the JWT authentication mechanism (CWE-347, Improper Verification of Cryptographic Signature). According to this entry, the authentication mechanism accepts tokens signed with algorithms other than those explicitly configured, which allows an attacker to create a JWT with an unsupported algorithm and gain unauthorized access, up to and including compromise of administrative accounts.

The CVSS scoring is also ambiguous: the original report cites 9.8, while the GitHub Advisory Database lists 9.8 for single-tenant deployments and an overall score of 10.0. The registry entry is marked as unreviewed, and the affected versions and specific WSO2 products are not specified. The primary WSO2 security advisory could not be obtained during verification, so the exact vulnerability class, affected versions, and authoritative CVSS score remain unresolved. Until WSO2 publishes its own confirmation, both descriptions should be treated with caution.

Impact assessment

Organizations running internet-exposed installations of Adobe Commerce and Magento Open Source face the greatest immediate risk. The CVSS vector for CVE-2026-71362 does not require any privileges or user interaction, and the public PoC makes exploitation technically accessible. Account takeover in online stores directly leads to leakage of personal data, compromise of payment information, and reputational damage.

For WSO2 products, risk assessment is complicated by the unresolved discrepancies in the vulnerability description. Regardless of whether this is a path traversal or a JWT authentication bypass, a CVSS score of 9.8+ indicates a critical threat to any WSO2 API platform deployments that are reachable over the network.

Recommendations

  • Adobe Commerce and Magento Open Source: immediately install the August 2026 updates (versions 2.4.x-2026-aug) or the corresponding standalone patches in accordance with the APSB26-92 advisory. Check logs for anomalous client session switches and unauthorized access to other users’ data — this is exactly the behavior demonstrated by the public PoC.
  • WSO2: monitor for publication of the official WSO2 security advisory for CVE-2026-5430 to obtain an accurate list of affected products and versions. Until the patch is released, consider restricting network access to WSO2 API gateways and management components.
  • General recommendation: the remediation deadline set by CISA for FCEB agencies is September 27, 2026. Commercial organizations should consider following the same timeline, especially for CVE-2026-71362, given the availability of a public PoC and the exploitation status confirmed by CISA.

CVE-2026-71362 in Adobe Commerce and Magento is the number one priority: a patch is available, the attack vector requires no privileges, and a public lab environment demonstrates account takeover. Install the APSB26-92 updates and review session logs. For CVE-2026-5430 in WSO2, wait for the vendor’s primary advisory, but restrict external access to affected components now — the discrepancies in the vulnerability description do not negate its critical rating or its presence in the KEV catalog.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.