Home / Sep 26, 2026 / Story
0
#5 The Hacker News general September 25, 2026 at 04:46 UTC

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

By [email protected] (The Hacker News)

AI Summary

CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-5430 (CVSS 9.8), a path traversal flaw in WSO2 API Control Plane, and a separate Adobe Commerce/Magento vulnerability, both confirmed as actively exploited. Federal agencies face mandatory remediation deadlines under BOD 22-01, and the WSO2 flaw's near-perfect severity score makes it a high-priority patch target for any enterprise using WSO2 middleware. Security teams should check for indicators of compromise alongside patching.

Relevance score: 82.0/100

# More from September 26