Download Privacy Needle App

Type to search

Cybersecurity

CISA Warns of Active Exploitation in WSO2, Adobe and SharePoint Flaws

Share

The US Cybersecurity and Infrastructure Security Agency (CISA) has added several critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue, noting that hackers are actively targeting enterprise software from WSO2, Adobe, and Microsoft.

Critical Flaws in WSO2 and Adobe Commerce

A critical authentication bypass vulnerability, tracked as CVE-2026-5430, is being exploited in WSO2 products. The flaw stems from the JSON Web Token (JWT) authentication mechanism, which incorrectly accepts tokens signed with unsupported algorithms. An attacker successfully exploiting this could compromise administrative accounts and gain full control over the affected systems.

The vulnerability impacts WSO2 API Manager versions 4.1.0 through 4.6.0, as well as the API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. Security firm watchTowr reported observing exploitation attempts in its honeypots, noting that WSO2 technology is widely used across the banking, government, telecommunications, and logistics sectors.

Adobe Commerce and Magento e-commerce platforms are also facing active exploitation through CVE-2026-71362. This incorrect authorisation vulnerability allows threat actors to gain access without requiring an existing account, administrator privileges, or any user interaction, according to security firm Sansec.

Microsoft SharePoint and Mikrotik Vulnerabilities

CISA also identified a high-severity code injection flaw in Microsoft SharePoint, tracked as CVE-2026-65660. Additionally, a medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS, identified as CVE-2026-67279, has been added to the list of vulnerabilities being leveraged in attacks.

Mitigation Deadlines for Federal Agencies

Federal agencies using the affected WSO2 and Adobe Commerce products have until Sunday, 27 September 2026, to apply recommended updates, mitigations, or discontinue use. For the vulnerabilities affecting Microsoft SharePoint and Mikrotik RouterOS, the deadline for agency action is Monday, 28 September 2026.

CISA encourages all organisations to prioritise patching these security issues immediately to prevent unauthorised access and system compromise.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.