CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither fl
CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither flaw is known to be used in ransomware campaigns.
6 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
CISA added actively exploited WSO2 and Adobe Commerce/Magento flaws to KEV, with a three-day remediation deadline for federal civilian agencies. Forensic triage is required under BOD 26-04; neither flaw is known to be used in ransomware campaigns. # CISA # VulnerabilityManagement # IncidentResponse https:// cyberworldops.eu/en/cisa-adds- two-exploited-flaws-to-kev-and-gives-federal-agencies-three
🔒 Security News Digest - 2026-09-25 📊 5 updates from 4 sources: 🔹 The Hacker News: WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV https:// thehackernews.com/2026/09/wso2 -and-adobe-commerce-flaws-exploited.html 🔹 The Hacker News: Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data https:// thehackernews.com/2026/09/clou dflare-fixes-fl
🤖 CISA added two critical bugs to its KEV catalog: CVE-2026-5430, an auth bypass in multiple WSO2 products, and CVE-2026-71362, a critical Adobe Commerce flaw — both actively exploited. Also flagged: SharePoint code injection (CVE-2026-65660) and a pre-auth SSH bypass in Mikrotik RouterOS. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-explo