(An Autonomous Body Recognized by Ministry of Commerce & Industry, Government of India)
Competency based placement focussed Education | Training | Research | Consultancy
C-6, Qutab Institutional Area, Near Old JNU Campus, New Delhi-110016
Regular | Part-time (Online Live Classes) Modes
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two serious software vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after security researchers identified evidence of active exploitation. The affected technologies include products from WSO2 and Adobe Commerce, including Magento.
One of the vulnerabilities, tracked as CVE-2026-5430, affects several WSO2 products, including API Control Plane, API Manager, Traffic Manager and Universal Gateway. The flaw can allow attackers to bypass security controls and upload files improperly, potentially giving them an opportunity to execute malicious code on an affected system. Security researchers reported seeing exploitation attempts against the vulnerability from at least 13 September.
The second vulnerability, identified as CVE-2026-71362, affects Adobe Commerce and Magento. It involves incorrect authorisation and can potentially allow an unauthenticated attacker to obtain elevated access to sensitive information without requiring interaction from the victim. Security researchers had previously reported attempts to exploit the weakness, including attacks capable of interfering with customer sessions and accessing private account information.
The inclusion of both vulnerabilities in CISA's KEV Catalog indicates that organisations should treat them as active security risks rather than merely theoretical weaknesses. Federal Civilian Executive Branch agencies in the United States have been directed to apply the available fixes by 27 September 2026.
CISA's action also highlights the need for organisations using affected software to review their systems, identify vulnerable installations and apply the relevant security updates. Prompt patching is particularly important when vulnerabilities have already been observed being used in real-world attacks.
The development demonstrates how quickly a software weakness can move from being a technical security issue to an immediate operational threat once attackers begin exploiting it.
24-09-2026