CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither fl

CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither flaw is known to be used in ransomware campaigns.

6 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither fl

mastodon:infosec-exchangeother4d ago kagi ↗

CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither flaw is known to be used in ransomware campaigns. # CISA # VulnerabilityManagement # IncidentResponse https:// cyberworldops.eu/en/cisa-adds- two-exploited-flaws-to-kev-and-gives-federal-agencies-three

🤖 CISA KEV: two actively exploited flaws added. CVE-2026-5430 (CVSS 9.8) — path traversal in WSO2 API Control Plane. Adobe Commerce/Magento flaw also exploited in the wild. Patch exposed instances no

mastodon:infosec-exchangeother4d ago kagi ↗

🤖 CISA KEV: two actively exploited flaws added. CVE-2026-5430 (CVSS 9.8) — path traversal in WSO2 API Control Plane. Adobe Commerce/Magento flaw also exploited in the wild. Patch exposed instances now. 🔗 https:// thehackernews.com/2026/09/wso2 -and-adobe-commerce-flaws-exploited.html # CVE # KEV # CyberSec

🔒 Security News Digest - 2026-09-25 📊 5 updates from 4 sources: 🔹 The Hacker News: WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV https:// thehackernews.com/2026/09/wso2 -and

mastodon:infosec-exchangeother4d ago kagi ↗

🔒 Security News Digest - 2026-09-25 📊 5 updates from 4 sources: 🔹 The Hacker News: WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV https:// thehackernews.com/2026/09/wso2 -and-adobe-commerce-flaws-exploited.html 🔹 The Hacker News: Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data https:// thehackernews.com/2026/09/clou dflare-fixes-fl

🤖 CISA added two critical bugs to its KEV catalog: CVE-2026-5430, an auth bypass in multiple WSO2 products, and CVE-2026-71362, a critical Adobe Commerce flaw — both actively exploited. Also flagged:

mastodon:infosec-exchangeother4d ago kagi ↗

🤖 CISA added two critical bugs to its KEV catalog: CVE-2026-5430, an auth bypass in multiple WSO2 products, and CVE-2026-71362, a critical Adobe Commerce flaw — both actively exploited. Also flagged: SharePoint code injection (CVE-2026-65660) and a pre-auth SSH bypass in Mikrotik RouterOS. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-explo

🤖 CISA KEV: CVE-2026-5430 (max severity) — JWT auth bypass in WSO2 API Manager 4.1.0-4.6.0 (plus API Control Plane/Traffic Manager/Universal Gateway 4.5-4.6). Forged tokens exposing API endpoints and

mastodon:infosec-exchangeother3d ago kagi ↗

🤖 CISA KEV: CVE-2026-5430 (max severity) — JWT auth bypass in WSO2 API Manager 4.1.0-4.6.0 (plus API Control Plane/Traffic Manager/Universal Gateway 4.5-4.6). Forged tokens exposing API endpoints and app credentials; watchTowr honeypots saw exploitation attempts. Fed fix deadline: Sep 27. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploi