Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

US Cybersecurity and Infrastructure Security Agency Adds Two Critical Vulnerabilities to Known Exploited Vulnerabilities (KEV) Catalog


US Cybersecurity and Infrastructure Security Agency Adds Two Critical Vulnerabilities to Known Exploited Vulnerabilities (KEV) Catalog. The agency has added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its KEV catalog, based on evidence of active exploitation. The vulnerabilities have a high level of risk and organizations are advised to apply fixes by September 27, 2026.

  • US Cybersecurity and Infrastructure Security Agency (CISA) added two critical security flaws to its Known Exploited Vulnerabilities (KEV) catalog.
  • CVE-2026-5430: Path traversal vulnerability in WSO2 API Control Plane, allowing unrestricted file upload and remote code execution.
  • CVE-2026-71362: Incorrect authorization vulnerability in Adobe Commerce and Magento, allowing elevated access to sensitive resources.
  • Federal Civilian Executive Branch (FCEB) agencies must apply fixes by September 27, 2026, to safeguard their networks.



  • The US Cybersecurity and Infrastructure Security Agency (CISA) has added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities, CVE-2026-5430 and CVE-2026-71362, are listed below.

    CVE-2026-5430 is a path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway that could allow unrestricted file upload and lead to remote code execution. This vulnerability has a CSV score of 9.8, indicating a high level of risk. The addition of CVE-2026-5430 to the KEV catalog comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026.

    CVE-2026-71362 is an incorrect authorization vulnerability in Adobe Commerce and Magento that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. This vulnerability has a CVSS score of 9.1, indicating a high level of risk. Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw. Previdian's telemetry indicates that a lone IP address from Australia attempted to exploit the flaw targeting its honeypot sensors on September 10, 2026. Adobe has yet to update its advisory to confirm exploitation status.

    Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats. It is essential for organizations to take immediate action to patch these vulnerabilities and prevent potential attacks.

    The addition of these vulnerabilities to the KEV catalog highlights the importance of ongoing vulnerability management and the need for organizations to stay vigilant in the face of emerging threats. It is crucial for organizations to prioritize cybersecurity and take proactive measures to protect their networks and systems from exploitation.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/US-Cybersecurity-and-Infrastructure-Security-Agency-Adds-Two-Critical-Vulnerabilities-to-Known-Exploited-Vulnerabilities-KEV-Catalog-ehn.shtml

  • https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html


  • Published: Fri Sep 25 02:02:16 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us