Tech News
← Home  ·  All topics

Wso2

1 GoKawiil brief on this topic

CISA adds WSO2, Adobe Commerce, SharePoint flaws to exploited vulnerabilities list

CISA has confirmed active exploitation of four vulnerabilities: a maximum-severity JWT authentication bypass in WSO2 API Manager and related products (CVE-2026-5430), a critical Adobe Commerce flaw (CVE-2026-71362), a high-severity SharePoint code injection bug (CVE-2026-65660), and a medium-severity Mikrotik RouterOS SSH bypass (CVE-2026-67279). Federal agencies must patch or mitigate the two critical flaws by September 27. Security firm watchTowr said its honeypots captured forged-token exploitation attempts against WSO2 systems starting September 13.