WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
Overview
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two significant vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to evidence that they are being actively exploited. One of the vulnerabilities, identified as CVE-2026-5430, is a path traversal flaw in WSO2 API Control Plane, which has a severity score of 9.8, indicating it's highly critical. The other vulnerability affects Adobe Commerce and Magento, although specific details about it were not provided in the article. Organizations using these platforms should be aware of the risks, as attackers may exploit these vulnerabilities to gain unauthorized access or control over systems. Immediate action is advised to mitigate potential threats from these vulnerabilities.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: WSO2 API Control Plane, Adobe Commerce, Magento
- Action Required: Organizations should promptly apply any available patches for WSO2 and Adobe Commerce.
- Timeline: Disclosed on October 26, 2023
Original Article Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,
Impact
WSO2 API Control Plane, Adobe Commerce, Magento
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed on October 26, 2023
Remediation
Organizations should promptly apply any available patches for WSO2 and Adobe Commerce. It is recommended to review system configurations and implement security best practices to minimize exposure to these vulnerabilities.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Exploit, Vulnerability, and 2 more.