hacker-news · Crawled Sep 25, 2026

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

1 CVEs
Read original article ↗

AI Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. CVE-2026-5430 is a path traversal flaw in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway that enables unrestricted file upload and remote code execution. CVE-2026-71362 is an incorrect authorization vulnerability in Adobe Commerce and Magento that allows attackers to escalate privileges and access sensitive customer data without user interaction. Exploitation of both vulnerabilities has been observed in the wild, with attacks detected as early as September 10, 2026.

AI-extracted · verify before operational use

Extracted Entities 1 found