CISA’s September 25 alert focuses on CVE-2026-5430, a maximum-severity authentication bypass vulnerability affecting multiple WSO2 products, including API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. The flaw stems from the JWT authentication mechanism accepting tokens signed with an unsupported algorithm, potentially allowing an attacker to compromise administrative accounts and take full control, according to WSO2’s original advisory from May 3.
Security firm watchTowr reported on September 15 that its honeypots captured exploitation attempts as early as September 13. Researchers observed limited activity from a single IP address using forged JWT tokens against a WSO2 product, though the attacker initially targeted the wrong product. watchTowr later reproduced the attack on the correct product, demonstrating that a forged token could expose API endpoints and application credentials.
“WSO2 is not a niche target,” said Yordan Ganchev, threat intelligence specialist at watchTowr. “Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics. Organizations in these sectors can't afford to wait for exploitation to be formally confirmed.”
The second critical flaw, CVE-2026-71362, is an incorrect authorization vulnerability in Adobe Commerce and Magento e-commerce platforms. Ecommerce security company Sansec has observed this flaw being exploited in the wild, noting that threat actors require “no existing account, administrator privileges, or user interaction” to leverage it.
CISA also flagged a high-severity code injection flaw in Microsoft SharePoint (CVE-2026-65660) and a medium-severity pre-authentication SSH state-machine bypass in Mikrotik RouterOS (CVE-2026-67279) as being exploited in attacks. While the September 27 deadline applies only to the two critical vulnerabilities for federal agencies, CISA encourages all organizations to prioritize addressing the security issues listed in the KEV catalog.