CISA Warns of Exploited Flaws in SharePoint, WSO2, Adobe

▼ Summary
– CISA has added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch WSO2 and Adobe Commerce products by September 27.
– The WSO2 flaw CVE-2026-5430 allows attackers to bypass authentication using forged JWT tokens, potentially compromising administrative accounts and full system control.
– The Adobe Commerce vulnerability CVE-2026-71362 enables unauthorized access without requiring existing accounts or administrator privileges, posing significant risks to e-commerce platforms.
– Two additional high-severity flaws in Microsoft SharePoint and Mikrotik RouterOS have been identified, with a mitigation deadline of September 28 for federal agencies.
– Security researchers from watchTowr and Sansec have confirmed active exploitation attempts in the wild, highlighting the urgent need for organizations across banking and government sectors to apply updates.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued urgent warnings regarding active exploitation of critical vulnerabilities across several major enterprise software platforms. The agency added two new entries to its Known Exploited Vulnerabilities (KEV) catalog, highlighting immediate threats from flaws in WSO2 products and Adobe Commerce. Federal agencies are now under strict orders to patch these specific issues or cease using the affected systems by Sunday, September 27.
In addition to the critical additions, CISA identified two other actively exploited flaws requiring attention. A high-severity code injection vulnerability in Microsoft SharePoint, tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine bypass in Mikrotik RouterOS, designated as CVE-2026-67279, are currently being leveraged by threat actors. While the deadline for addressing these two specific issues is set for Monday, September 28, the urgency surrounding the WSO2 and Adobe flaws remains paramount due to their critical severity ratings.
The first critical flaw, CVE-2026-5430, represents a severe authentication bypass affecting multiple versions of WSO2 API Manager (4.1.0 through 4.6.0), as well as the API Control Plane, Traffic Manager, and Universal Gateway (versions 4.5.0 and 4.6.0). This vulnerability stems from the JWT authentication mechanism’s failure to reject tokens signed with unsupported algorithms. According to the vendor’s original advisory released on May 3, successful exploitation allows an attacker to compromise administrative accounts and gain full control over the system.
Although CISA has not disclosed specific details about ongoing attacks, security firm watchTowr provided evidence of exploitation attempts via its honeypots on September 15. Researchers observed limited activity from a single IP address on September 13, where forged JWT tokens were used against a WSO2 product. Notably, the initial attempt targeted the wrong product variant for CVE-2026-5430. However, watchTowr successfully reproduced the attack on the correct product configuration, demonstrating that a forged token could expose API endpoints and application credentials.
Yordan Ganchev, threat intelligence specialist at watchTowr, emphasized the widespread relevance of this risk.
“Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics,” explained Ganchev. “Organizations in these sectors can’t afford to wait for exploitation to be formally confirmed.”
The second critical vulnerability added to the KEV list is CVE-2026-71362, an incorrect authorization flaw impacting Adobe Commerce and Magento e-commerce platforms. Ecommerce security company Sansec reported observing this flaw being exploited in the wild. The researchers noted that the vulnerability is particularly dangerous because it requires “no existing account, administrator privileges, or user interaction” for threat actors to leverage it effectively.
While the September 27 deadline applies specifically to federal entities managing the WSO2 and Adobe vulnerabilities, CISA strongly encourages all organizations to prioritize remediation efforts for every item listed in the KEV catalog. The rapid pace of exploitation underscores the necessity for immediate action across both public and private sectors to mitigate potential breaches.
(Source: BleepingComputer)




