CISA adds WSO2, Adobe Commerce, SharePoint flaws to exploited vulnerabilities list
CISA has confirmed active exploitation of four vulnerabilities: a maximum-severity JWT authentication bypass in WSO2 API Manager and related products (CVE-2026-5430), a critical Adobe Commerce flaw (CVE-2026-71362), a high-severity SharePoint code injection bug (CVE-2026-65660), and a medium-severity Mikrotik RouterOS SSH bypass (CVE-2026-67279). Federal agencies must patch or mitigate the two critical flaws by September 27. Security firm watchTowr said its honeypots captured forged-token exploitation attempts against WSO2 systems starting September 13.
GoKawiil's interpretation of the reporting above, not reported fact.
The WSO2 flaw could let attackers forge authentication tokens to seize administrative control and expose API credentials, which watchTowr researchers say makes it especially dangerous for enterprises relying on WSO2's API management stack. CISA's binding directive to federal agencies signals these bugs are being actively weaponized rather than theoretical risks, suggesting private-sector organizations using the same products should treat patching as urgent.
- CISA added CVE-2026-5430 (WSO2) and CVE-2026-71362 (Adobe Commerce) to its Known Exploited Vulnerabilities catalog as critical, exploited flaws.
- Federal agencies have until September 27 to patch or stop using affected WSO2 and Adobe Commerce products.
- watchTowr researchers observed real-world forged-token attack attempts against WSO2 systems starting September 13, though an early attempt targeted the wrong product.
Source: bleepingcomputer.com, 2026-09-25
Published there as: “CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.