CISA Warns of Active Exploitation in WSO2, Adobe and SharePoint Flaws
Share
The US Cybersecurity and Infrastructure Security Agency (CISA) has added several critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue, noting that hackers are actively targeting enterprise software from WSO2, Adobe, and Microsoft.
Critical Flaws in WSO2 and Adobe Commerce
A critical authentication bypass vulnerability, tracked as CVE-2026-5430, is being exploited in WSO2 products. The flaw stems from the JSON Web Token (JWT) authentication mechanism, which incorrectly accepts tokens signed with unsupported algorithms. An attacker successfully exploiting this could compromise administrative accounts and gain full control over the affected systems.
The vulnerability impacts WSO2 API Manager versions 4.1.0 through 4.6.0, as well as the API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. Security firm watchTowr reported observing exploitation attempts in its honeypots, noting that WSO2 technology is widely used across the banking, government, telecommunications, and logistics sectors.
Adobe Commerce and Magento e-commerce platforms are also facing active exploitation through CVE-2026-71362. This incorrect authorisation vulnerability allows threat actors to gain access without requiring an existing account, administrator privileges, or any user interaction, according to security firm Sansec.
Microsoft SharePoint and Mikrotik Vulnerabilities
CISA also identified a high-severity code injection flaw in Microsoft SharePoint, tracked as CVE-2026-65660. Additionally, a medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS, identified as CVE-2026-67279, has been added to the list of vulnerabilities being leveraged in attacks.
Mitigation Deadlines for Federal Agencies
Federal agencies using the affected WSO2 and Adobe Commerce products have until Sunday, 27 September 2026, to apply recommended updates, mitigations, or discontinue use. For the vulnerabilities affecting Microsoft SharePoint and Mikrotik RouterOS, the deadline for agency action is Monday, 28 September 2026.
CISA encourages all organisations to prioritise patching these security issues immediately to prevent unauthorised access and system compromise.




Leave a Reply