Overview
- CISA formally added CVE-2026-5430 (WSO2) and CVE-2026-71362 (Adobe Commerce/Magento) to its KEV catalog on Friday and set a remediation deadline of September 27 for Federal Civilian Executive Branch agencies.
- CVE-2026-5430 is a critical WSO2 flaw in JWT signature verification that allows path traversal and unrestricted file upload and can lead to remote code execution in WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway.
- CVE-2026-71362 is an incorrect-authorization bug in Adobe Commerce and Magento that can let unauthenticated attackers switch customer sessions, hijack accounts, and access private customer data and Adobe has released isolated patches in APSB26-92.
- Security firms have seen real-world activity tied to both flaws: watchTowr captured forged JWTs and reproduced the WSO2 exploit on September 13, Previdian logged a single-IP probe against the Adobe bug on September 10, and Sansec reported blocking Adobe exploitation attempts.
- Because WSO2 is widely deployed across banking, government, telecom and logistics, defenders are urged to apply vendor patches, isolate exposed management interfaces, deploy blocking and detection controls, and run forensic hunts for signs of compromise.