WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included two critical security flaws impacting WSO2 and Adobe Commerce and Magento in its Known Exploited Vulnerabilities (KEV) catalog, following evidence of active exploitation.
Vulnerabilities Exploited
- CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane.
- CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in Adobe Commerce.
The vulnerabilities have been exploited in ongoing attacks, highlighting the importance of patching and updating software systems to prevent potential data breaches and cyber threats.
CISA urges users of affected products to apply the necessary security patches and updates to mitigate the risks associated with these vulnerabilities.
</body> </html><small>Source: The Hacker News — read the original story there.</small>