Skip to content

CISA adds WSO2 and Adobe Commerce flaws to its exploited list

A JWT authentication bypass in WSO2 API Manager and an authorization flaw in Adobe Commerce and Magento are now on the Known Exploited Vulnerabilities catalogue, with a federal patch deadline of 27 September.

Source: CISA

CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalogue on 24 September, and gave federal civilian agencies until today, 27 September, to patch them.

The first, CVE-2026-5430, is a JWT authentication bypass in WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway: a token signed with an unsupported algorithm slips past validation and hands over admin accounts. It scores CVSS 10.0 (9.8 for single-tenant setups), affects API Manager 4.1.0 through 4.6.0, and was patched back in May in advisory WSO2-2026-5328. WatchTowr says it has tracked forged-JWT exploitation attempts against its honeypots since 13 September. The second, CVE-2026-71362 in Adobe Commerce and Magento, needs no account or login at all: it lets an attacker switch a customer’s session to someone else’s, and was fixed in August’s APSB26-92 security bulletin. Sansec spotted exploitation attempts the same month it was patched.

Why it matters: both fixes have been available for months, which is exactly why they made the exploited list — attackers had a long, quiet window to build working exploits before anyone was in a hurry to apply them. If you run WSO2 API Manager or Adobe Commerce/Magento and skipped those updates, treat this as active, not theoretical.

The caveat: the CISA deadline binds only US federal agencies. Everyone else just gets to notice that both flaws are now being exploited in the wild, deadline or not.

Share

Related reading

More from The Wire

All briefs