Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Live: Pope Leo arrives at Élysée presidential palace on landmark visit to France

    September 25, 2026

    FBI investigating claim hackers have stolen details of all its agents

    September 25, 2026

    Hackers steal $351.6 million in Bitget crypto exchange hack

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Live: Pope Leo arrives at Élysée presidential palace on landmark visit to France
    • FBI investigating claim hackers have stolen details of all its agents
    • Hackers steal $351.6 million in Bitget crypto exchange hack
    • Solana DEX volume spike hides circular trades, and automated bots are blamed
    • Explosive Intensification for Hurricane Polo
    • Fossil fuel subsidies are the ‘worst energy policy in the world,’ researchers say
    • North Sea appraisal ops up the oil & gas discoveries’ projected size
    • Thank you, Phil Gates, for nearly 40 years of country diaries | The Guardian
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 25, 2026Vulnerability / Web Security

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

    The vulnerabilities are listed below –

    • CVE-2026-5430 (CVS score: 9.8) – A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remote code execution.
    • CVE-2026-71362 (CVSS score: 9.1) – An incorrect authorization vulnerability in Adobe Commerce and Magento that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

    The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it’s seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026.

    Cybersecurity

    As for CVE-2026-71362, Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw.

    “The vulnerability lets attackers switch a customer session to another customer account,” the Dutch e-commerce security company said. “This gives them access to the victim’s account and private customer data.”

    Previdian’s telemetry indicates that a lone IP address from Australia attempted to exploit the flaw targeting its honeypot sensors on September 10, 2026. Adobe has yet to update its advisory to confirm exploitation status.

    Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats.

    added Adobe attacks CISA commerce Exploited flaws KEV WSO2
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers steal $351.6 million in Bitget crypto exchange hack

    Roundcube Webmail Vulnerability in Attackers’ Crosshairs

    Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data

    17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

    New Carbonato malware uses AI agents to hijack exposed Docker hosts

    WordPress patches a critical severity security vulnerability

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Live: Pope Leo arrives at Élysée presidential palace on landmark visit to France

    September 25, 2026

    FBI investigating claim hackers have stolen details of all its agents

    September 25, 2026

    Hackers steal $351.6 million in Bitget crypto exchange hack

    September 25, 2026

    Solana DEX volume spike hides circular trades, and automated bots are blamed

    September 25, 2026
    Latest Posts

    Spain’s Pedro Sánchez is a progressive outlier in Europe – and over Ceuta, he is being made to pay for it | Eoghan Gilmartin

    August 6, 2026

    Putin Signs Law For Russia To Regulate Crypto Exchanges

    August 6, 2026

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Live: Pope Leo arrives at Élysée presidential palace on landmark visit to France

    September 25, 2026

    FBI investigating claim hackers have stolen details of all its agents

    September 25, 2026

    Hackers steal $351.6 million in Bitget crypto exchange hack

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.