{"id":258150,"date":"2026-09-26T23:29:47","date_gmt":"2026-09-26T20:29:47","guid":{"rendered":"https:\/\/digitrendz.blog\/z\/?p=258150"},"modified":"2026-09-26T23:29:47","modified_gmt":"2026-09-26T20:29:47","slug":"cisa-warns-of-exploited-flaws-in-sharepoint-wso2-adobe","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/digital-marketing\/258150\/cisa-warns-of-exploited-flaws-in-sharepoint-wso2-adobe\/","title":{"rendered":"CISA Warns of Exploited Flaws in SharePoint, WSO2, Adobe"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\" open=\"\"><summary>\u25bc Summary<\/summary><p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; CISA has added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch WSO2 and Adobe Commerce products by September 27.<br>&#8211; The WSO2 flaw CVE-2026-5430 allows attackers to bypass authentication using forged JWT tokens, potentially compromising administrative accounts and full system control.<br>&#8211; The Adobe Commerce vulnerability CVE-2026-71362 enables unauthorized access without requiring existing accounts or administrator privileges, posing significant risks to e-commerce platforms.<br>&#8211; Two additional high-severity flaws in Microsoft SharePoint and Mikrotik RouterOS have been identified, with a mitigation deadline of September 28 for federal agencies.<br>&#8211; Security researchers from watchTowr and Sansec have confirmed active exploitation attempts in the wild, highlighting the urgent need for organizations across banking and government sectors to apply updates.<br><\/p><\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">T<\/mark>he <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/cybersecurity-and-infrastructure-security-agency\/\" class=\"acp-entity-link\" data-entity-id=\"29085\" data-entity-category=\"Organization\" title=\"Learn more about Cybersecurity and Infrastructure Security Agency\" target=\"_blank\" rel=\"noopener noreferrer\">Cybersecurity and Infrastructure Security Agency<\/a> (<a href=\"https:\/\/digitrendz.blog\/z\/entity\/cisa\/\" class=\"acp-entity-link\" data-entity-id=\"21358\" data-entity-category=\"Organization\" title=\"Learn more about CISA\" target=\"_blank\" rel=\"noopener noreferrer\">CISA<\/a>)<\/strong> has issued urgent warnings regarding active exploitation of critical vulnerabilities across several major enterprise software platforms. The agency added two new entries to its <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/known-exploited-vulnerabilities\/\" class=\"acp-entity-link\" data-entity-id=\"95717\" data-entity-category=\"product\" title=\"Learn more about Known Exploited Vulnerabilities\" target=\"_blank\" rel=\"noopener noreferrer\">Known Exploited Vulnerabilities<\/a> (KEV)<\/strong> catalog, highlighting immediate threats from flaws in <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/wso2\/\" class=\"acp-entity-link\" data-entity-id=\"301865\" data-entity-category=\"Organization\" title=\"Learn more about WSO2\" target=\"_blank\" rel=\"noopener noreferrer\">WSO2<\/a><\/strong> products and <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/adobe-commerce\/\" class=\"acp-entity-link\" data-entity-id=\"141689\" data-entity-category=\"product\" title=\"Learn more about Adobe Commerce\" target=\"_blank\" rel=\"noopener noreferrer\">Adobe Commerce<\/a><\/strong>. Federal agencies are now under strict orders to patch these specific issues or cease using the affected systems by <strong>Sunday, September 27<\/strong>.<\/p>\n\n<p class=\"wp-block-paragraph\">In addition to the critical additions, CISA identified two other actively exploited flaws requiring attention. A high-severity code injection vulnerability in <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/microsoft-sharepoint\/\" class=\"acp-entity-link\" data-entity-id=\"64031\" data-entity-category=\"Technology\" title=\"Learn more about Microsoft SharePoint\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft SharePoint<\/a><\/strong>, tracked as <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/cve-2026-65660\/\" class=\"acp-entity-link\" data-entity-id=\"301870\" data-entity-category=\"Technology\" title=\"Learn more about CVE-2026-65660\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2026-65660<\/a><\/strong>, and a medium-severity pre-authentication SSH state-machine bypass in <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/mikrotik-routeros\/\" class=\"acp-entity-link\" data-entity-id=\"301866\" data-entity-category=\"product\" title=\"Learn more about Mikrotik RouterOS\" target=\"_blank\" rel=\"noopener noreferrer\">Mikrotik RouterOS<\/a><\/strong>, designated as <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/cve-2026-67279\/\" class=\"acp-entity-link\" data-entity-id=\"301871\" data-entity-category=\"Technology\" title=\"Learn more about CVE-2026-67279\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2026-67279<\/a><\/strong>, are currently being leveraged by threat actors. While the deadline for addressing these two specific issues is set for <strong>Monday, September 28<\/strong>, the urgency surrounding the WSO2 and Adobe flaws remains paramount due to their critical severity ratings.<\/p>\n\n<p class=\"wp-block-paragraph\">The first critical flaw, <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/cve-2026-5430\/\" class=\"acp-entity-link\" data-entity-id=\"301868\" data-entity-category=\"Technology\" title=\"Learn more about CVE-2026-5430\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2026-5430<\/a><\/strong>, represents a severe authentication bypass affecting multiple versions of <strong>WSO2 API Manager<\/strong> (4.1.0 through 4.6.0), as well as the <a href=\"https:\/\/digitrendz.blog\/z\/entity\/api-control-plane\/\" class=\"acp-entity-link\" data-entity-id=\"301876\" data-entity-category=\"product\" title=\"Learn more about API Control Plane\" target=\"_blank\" rel=\"noopener noreferrer\">API Control Plane<\/a>, <a href=\"https:\/\/digitrendz.blog\/z\/entity\/traffic-manager\/\" class=\"acp-entity-link\" data-entity-id=\"301874\" data-entity-category=\"product\" title=\"Learn more about Traffic Manager\" target=\"_blank\" rel=\"noopener noreferrer\">Traffic Manager<\/a>, and <a href=\"https:\/\/digitrendz.blog\/z\/entity\/universal-gateway\/\" class=\"acp-entity-link\" data-entity-id=\"301875\" data-entity-category=\"product\" title=\"Learn more about Universal Gateway\" target=\"_blank\" rel=\"noopener noreferrer\">Universal Gateway<\/a> (versions 4.5.0 and 4.6.0). This vulnerability stems from the <a href=\"https:\/\/digitrendz.blog\/z\/entity\/jwt-authentication-mechanism\/\" class=\"acp-entity-link\" data-entity-id=\"301872\" data-entity-category=\"Technology\" title=\"Learn more about JWT authentication mechanism\" target=\"_blank\" rel=\"noopener noreferrer\">JWT authentication mechanism<\/a>\u2019s failure to reject tokens signed with unsupported algorithms. According to the vendor\u2019s original advisory released on May 3, successful exploitation allows an attacker to compromise administrative accounts and gain full control over the system.<\/p>\n\n<p class=\"wp-block-paragraph\">Although CISA has not disclosed specific details about ongoing attacks, security firm <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/watchtowr\/\" class=\"acp-entity-link\" data-entity-id=\"30754\" data-entity-category=\"Organization\" title=\"Learn more about watchTowr\" target=\"_blank\" rel=\"noopener noreferrer\">watchTowr<\/a><\/strong> provided evidence of exploitation attempts via its honeypots on September 15. Researchers observed limited activity from a single IP address on September 13, where forged JWT tokens were used against a WSO2 product. Notably, the initial attempt targeted the wrong product variant for CVE-2026-5430. However, watchTowr successfully reproduced the attack on the correct product configuration, demonstrating that a forged token could expose API endpoints and application credentials.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Yordan Ganchev, threat intelligence specialist at watchTowr<\/strong>, emphasized the widespread relevance of this risk.<\/p>\n\n<p class=\"wp-block-paragraph\">\u201cIts technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics,\u201d explained Ganchev. \u201cOrganizations in these sectors can&#8217;t afford to wait for exploitation to be formally confirmed.\u201d<\/p>\n\n<p class=\"wp-block-paragraph\">The second critical vulnerability added to the KEV list is <strong>CVE-2026-71362<\/strong>, an incorrect authorization flaw impacting <strong>Adobe Commerce<\/strong> and <strong>Magento<\/strong> e-commerce platforms. Ecommerce security company <strong>Sansec<\/strong> reported observing this flaw being exploited in the wild. The researchers noted that the vulnerability is particularly dangerous because it requires &#8220;no existing account, administrator privileges, or user interaction&#8221; for threat actors to leverage it effectively.<\/p>\n\n<p class=\"wp-block-paragraph\">While the September 27 deadline applies specifically to federal entities managing the WSO2 and Adobe vulnerabilities, CISA strongly encourages all organizations to prioritize remediation efforts for every item listed in the KEV catalog. The rapid pace of exploitation underscores the necessity for immediate action across both public and private sectors to mitigate potential breaches.<\/p>\n\n<em>(Source: <a href='https:\/\/bleepingcomputer.com\/news\/security\/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks\/' target='_blank'>BleepingComputer<\/a>)<\/em>","protected":false},"excerpt":{"rendered":"<p>CISA has added critical vulnerabilities in WSO2 products and Adobe Commerce to its Known Exploited Vulnerabilities catalog, mandating that federal agencies patch these issues or cease using the affected systems by September 27. Two additional actively exploited flaws were identified: a high-sever&#8230;<\/p>\n","protected":false},"author":1,"featured_media":258160,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[57,18],"tags":[],"entities":[106383,258742,258741,59998,14622,258738,258740,258736,258739,20805,258745,60499,26938,43213,258737,106386,258743,258744,22086,258734,258735],"class_list":["post-258150","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","category-digital-marketing","entity-adobe-commerce","entity-api-control-plane","entity-api-manager","entity-bleepingcomputer-2","entity-cisa","entity-cve-2026-5430","entity-cve-2026-65660","entity-cve-2026-67279","entity-cve-2026-71362","entity-cybersecurity-and-infrastructure-security-agency","entity-jwt-authentication-mechanism","entity-known-exploited-vulnerabilities","entity-magento","entity-microsoft-sharepoint","entity-mikrotik-routeros","entity-sansec","entity-traffic-manager","entity-universal-gateway","entity-watchtowr","entity-wso2","entity-yordan-ganchev"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/258150","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=258150"}],"version-history":[{"count":2,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/258150\/revisions"}],"predecessor-version":[{"id":258161,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/258150\/revisions\/258161"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/258160"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=258150"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=258150"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=258150"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=258150"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}