TL;DR
On September 24, 2026, CISA updated its Known Exploited Vulnerabilities catalog with two high-risk security flaws. These critical CISA KEV vulnerabilities impact enterprise deployments of WSO2 and Adobe Commerce. Federal agencies and corporate administrators must remediate these flaws immediately to prevent network compromise.
- Product: WSO2 Universal Gateway, Adobe Commerce
- Vulnerabilities: 2 flaws (CVE-2026-5430, CVE-2026-71362)
- Highest severity: 10.0 (Critical · CVSSv3)
- Worst impact: Authentication Bypass via JWT Algorithm Mismatch in Multiple Products Allows Account Takeover
- Status: 2 exploited; patches available
- Action: Update to 4.5.0.57, 4.6.0.21, 4.5.0.56, 4.5.0.58 (+15) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-5430 | 10 | CWE-347 | 4.5.0.57, 4.6.0.21, 4.5.0.56 (+13) | Exploited |
| CVE-2026-71362 | 9.1 | CWE-863 | 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug, 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug, 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug | Exploited |
Track every Adobe CVE the moment it's exploited.
Get free email alertsWhy It Matters
Sourced estimates show that tens of thousands of organizations deploy WSO2 middleware and Adobe Commerce storefronts globally. Consequently, security defects in these platforms create substantial exposure for enterprise systems. The Cybersecurity and Infrastructure Security Agency confirmed that adversaries actively exploit both flaws in the wild. Furthermore, the WSO2 issue carries a maximum CVSS rating of 10.0. Meanwhile, the Adobe flaw holds a CVSS score of 9.1. Fortunately, researchers have not observed any public proof-of-concept exploit code for these defects. However, unpatched internet-facing servers face immediate risk of account takeover.
How The Attack Works
The two vulnerabilities exploit different application flaws to achieve privilege escalation. The WSO2 defect, tracked as CVE-2026-5430, involves broken JSON Web Token verification. An unauthenticated attacker transmits a token signed with an unsupported algorithm. The server accepts the malformed token and bypasses authentication checks. In contrast, the Adobe flaw tracked as CVE-2026-71362 involves incorrect authorization logic. An attacker exploits this flaw to gain elevated access to restricted resources without user interaction.
Affected Versions
The WSO2 flaw impacts API Manager versions 4.1.0 through 4.6.0. It also affects WSO2 API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. Meanwhile, the Adobe vulnerability affects Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9. Installations prior to the August 2026 security release remain vulnerable.
Patch Or Mitigation Steps
Administrators must install vendor patches immediately to secure their environments. Open-source users can apply pull requests from the WSO2 security advisory. Subscription holders should apply the latest product update levels. For e-commerce systems, teams must upgrade installations using the Adobe Commerce security update guide. Federal civilian agencies must resolve both CISA KEV vulnerabilities before September 27, 2026. Rapid patching protects enterprise infrastructure from active exploitation.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!