CISA Warns of Four Actively Exploited Flaws in WSO2, Adobe Commerce, Microsoft SharePoint, Mikrotik RouterOS

Federal agencies given until September 27 to patch critical WSO2 and Adobe Commerce vulnerabilities.

edit
By LineZotpaper
Published
Read Time2 min
The Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, warning that hackers are actively exploiting critical flaws in enterprise software from WSO2 and Adobe, along with high- and medium-severity bugs in Microsoft SharePoint and Mikrotik RouterOS. Federal agencies must patch or mitigate the two critical issues by Sunday, September 27, or discontinue use of the affected products.

CISA’s September 25 alert focuses on CVE-2026-5430, a maximum-severity authentication bypass vulnerability affecting multiple WSO2 products, including API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. The flaw stems from the JWT authentication mechanism accepting tokens signed with an unsupported algorithm, potentially allowing an attacker to compromise administrative accounts and take full control, according to WSO2’s original advisory from May 3.

Security firm watchTowr reported on September 15 that its honeypots captured exploitation attempts as early as September 13. Researchers observed limited activity from a single IP address using forged JWT tokens against a WSO2 product, though the attacker initially targeted the wrong product. watchTowr later reproduced the attack on the correct product, demonstrating that a forged token could expose API endpoints and application credentials.

“WSO2 is not a niche target,” said Yordan Ganchev, threat intelligence specialist at watchTowr. “Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics. Organizations in these sectors can't afford to wait for exploitation to be formally confirmed.”

The second critical flaw, CVE-2026-71362, is an incorrect authorization vulnerability in Adobe Commerce and Magento e-commerce platforms. Ecommerce security company Sansec has observed this flaw being exploited in the wild, noting that threat actors require “no existing account, administrator privileges, or user interaction” to leverage it.

CISA also flagged a high-severity code injection flaw in Microsoft SharePoint (CVE-2026-65660) and a medium-severity pre-authentication SSH state-machine bypass in Mikrotik RouterOS (CVE-2026-67279) as being exploited in attacks. While the September 27 deadline applies only to the two critical vulnerabilities for federal agencies, CISA encourages all organizations to prioritize addressing the security issues listed in the KEV catalog.

§

Analysis

Why This Matters

  • The vulnerabilities affect widely deployed enterprise software: WSO2 serves nearly 1,000 customers in critical sectors, and Adobe Commerce powers a large share of online retail.
  • Federal agencies face a tight deadline to remediate the two critical flaws, highlighting the urgency of the threat.
  • Exploitation is already underway, with watchTowr detecting attempts and Sansec confirming in-the-wild attacks on Adobe Commerce.

Background

CISA’s Known Exploited Vulnerabilities (KEV) catalog is a repository of flaws that have been confirmed as actively exploited in the wild. Federal civilian executive branch agencies are required to patch KEV-listed vulnerabilities within specific timelines, typically two weeks. WSO2 is an open-source enterprise integration platform used heavily in finance, telecommunications, and government. Adobe Commerce (formerly Magento) is a popular e-commerce platform. The two additional flaws in Microsoft SharePoint and Mikrotik RouterOS expand the scope of this warning to a broader set of organizations.

Key Perspectives

watchTowr (security researchers): Their honeypot data shows active scanning and exploitation attempts against WSO2 products. They stress that organizations should not wait for formal confirmation of exploitation before patching, given the high risk to critical infrastructure. CISA (regulatory authority): By adding these flaws to the KEV catalog, CISA is signaling that immediate action is required, at least for government agencies. The agency’s guidance is often adopted by private-sector organizations seeking to align with best practices. Vendors (WSO2, Adobe, Microsoft, Mikrotik): Patches or mitigations have been issued. WSO2 released an advisory in May; Adobe and Microsoft typically ship security updates via their regular cycles. The onus is on system administrators to apply fixes promptly.

What to Watch

  • Whether additional exploitation campaigns emerge as details of the vulnerabilities become more widely known.
  • Federal agencies’ compliance with the September 27 deadline, which could set a precedent for future timelines.
  • Potential for proof-of-concept code to be published, increasing risk for unpatched systems.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.