CISA Warns of Active Exploitation Targeting WSO2, Adobe Commerce, SharePoint and MikroTik Flaws
The Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities affecting WSO2, Adobe Commerce, Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog.
The agency is warning that attackers are actively exploiting the flaws and urging organizations to apply the recommended updates or mitigations as soon as possible.
WSO2 authentication bypass exploited in attacks
The most serious issue is CVE-2026-5430, a critical authentication bypass vulnerability affecting multiple WSO2 enterprise software products.
The vulnerability affects WSO2 API Manager versions 4.1.0 through 4.6.0, as well as API Control Plane, Traffic Manager and Universal Gateway versions 4.5.0 and 4.6.0.
According to the NVD vulnerability record and WSO2’s original security advisory, the flaw is caused by the JWT authentication mechanism accepting tokens signed with unsupported algorithms.
An attacker who successfully exploits the vulnerability could compromise administrative accounts and take complete control of affected systems.
CISA has not released details about the attacks. However, security firm watchTowr reported on September 15 that its honeypot had captured an exploitation attempt.
Researchers observed a limited number of attempts involving forged JWT tokens against WSO2 products from a single IP address on September 13. The attacker initially targeted the wrong product for CVE-2026-5430.
watchTowr later reproduced the attack against a legitimate product, where a forged token could expose API endpoints and application credentials.
Yordan Ganchev, a threat intelligence expert at watchTowr, told BleepingComputer that WSO2 is used by approximately 1,000 customers in the banking, government, telecommunications and logistics sectors.
“Organizations in these sectors cannot afford to wait for exploits to be officially confirmed,” Ganchev said.
Adobe Commerce and Magento flaw exploited in the wild
CISA also added CVE-2026-71362, a critical incorrect authentication vulnerability affecting Adobe Commerce and Magento e-commerce platforms.
E-commerce security firm Sansec has observed the vulnerability being exploited in the wild. The company said that exploitation does not require an existing account, administrative privileges or user interaction.
SharePoint and MikroTik RouterOS vulnerabilities under attack
The other two vulnerabilities added to the KEV catalog are a high-severity code injection flaw in Microsoft SharePoint, tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state machine and workflow bypass in MikroTik RouterOS, tracked as CVE-2026-67279.
CISA deadlines for federal agencies
Under CISA’s directive, federal agencies using products affected by CVE-2026-5430 and CVE-2026-71362 have until September 27 to apply the recommended updates or mitigations, or discontinue their use.
Federal agencies have until September 28 to address the Microsoft SharePoint and MikroTik RouterOS vulnerabilities.
Although the deadlines apply to federal agencies, CISA encourages all organizations to prioritize vulnerabilities listed in the KEV catalog and take immediate action to protect affected systems.
Join Mikko Hypponen and security leaders from the NFL, Chanel and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix and revalidate at machine speed.
Source: www.bleepingcomputer.com



