Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Inpex beefs up stake in Australian LNG project

    September 25, 2026

    Ethiopia, TPLF Rebels Return to War in Tigray Region

    September 25, 2026

    Small boat crossings didn’t start after the Brexit referendum – Full Fact

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Inpex beefs up stake in Australian LNG project
    • Ethiopia, TPLF Rebels Return to War in Tigray Region
    • Small boat crossings didn’t start after the Brexit referendum – Full Fact
    • Russia-Ukraine war: Moscow targeting ‘ordinary life’ with attacks on data centres, Zelensky says
    • Tory ex-ministers face serious questions over migrant centre chaos, inquiry hears
    • Glasgow City Council pauses plan to fire and rehire 23,000 staff
    • Meta opens early access program for new Muse features
    • CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.

    The agency also added CVE-2026-71362, another critical-severity flaw affecting Adobe Commerce, to the list of security issues being leveraged in attacks.

    Hackers are also exploiting two additional vulnerabilities: a high-severity code injection flaw in Microsoft SharePoint tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS identified as CVE-2026-67279.

    For the two critical issues added to the Known Exploited Vulnerabilities (KEV) catalog, federal agencies using the affected products have until  Sunday, September 27, to apply the recommended updates or mitigations, or discontinue their use.

    The CVE-2026-5430 flaw received a maximum severity score and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.

    In the original advisory on May 3, the vendor says that an attacker successfully exploiting the vulnerability could compromise administrative accounts and take full control.

    The problem stems from the JWT authentication mechanism accepting tokens signed with an unsupported algorithm.

    CISA has not shared any details about the attacks, but security firm watchTowr announced on September 15 announced that its honeypots captured exploitation attempts.

    The researchers said they observed a limited number of attempts from one IP address on September 13 using forged JWT tokens against a WSO2 product. However, the attacker targeted the wrong product for CVE-2026-5430.

    watchTowr reproduced the attack on the correct product, where a forged token could expose API endpoints and application credentials.

    Yordan Ganchev, threat intelligence specialist at watchTowr, told BleepingComputer that WSO2 is not a niche target.

    “Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics,” explained Ganchev.

    “Organizations in these sectors can’t afford to wait for exploitation to be formally confirmed.”

    The second critical-severity bug added to the KEV is CVE-2026-71362, an incorrect authorization vulnerability in Adobe’s Commerce and Magento e-commerce platforms.

    Ecommerce security company Sansec observed CVE-2026-71362 being exploited in the wild, saying that threat actors require “no existing account, administrator privileges, or user interaction” to leverage it.

    The deadline for federal agencies to mitigate both vulnerabilities is September 27, but CISA encourages all organizations to take action and prioritize addressing the security issues listed in the KEV.

    For the Microsoft SharePoint and Mikrotik RouterOS flaws, CISA is giving agencies until Monday, September 28 to fix them.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Adobe attacks CISA commerce Exploited flaws SharePoint warns WSO2
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Russia-Ukraine war: Moscow targeting ‘ordinary life’ with attacks on data centres, Zelensky says

    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    Republican Ad Attacks Cooper with Misleading Claim About Rape Kits

    Elementor WordPress flaw lets attackers create admin accounts

    Pope warns against ‘losing humanity’ to AI machines

    Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Inpex beefs up stake in Australian LNG project

    September 25, 2026

    Ethiopia, TPLF Rebels Return to War in Tigray Region

    September 25, 2026

    Small boat crossings didn’t start after the Brexit referendum – Full Fact

    September 25, 2026

    Russia-Ukraine war: Moscow targeting ‘ordinary life’ with attacks on data centres, Zelensky says

    September 25, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Inpex beefs up stake in Australian LNG project

    September 25, 2026

    Ethiopia, TPLF Rebels Return to War in Tigray Region

    September 25, 2026

    Small boat crossings didn’t start after the Brexit referendum – Full Fact

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.