EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 95/100

CISA ha aggiunto due vulnerabilità critiche, CVE-2026-5430 e CVE-2026-71362, al KEV a causa di sfruttamenti attivi. La prima riguarda un problema di path traversal in WSO2, mentre la seconda è un errore di autorizzazione in Adobe Commerce. Le aziende devono applicare patch entro il 27 settembre 2026 per proteggersi.

Why it matters

Le PMI italiane sono a rischio di accessi non autorizzati e furto di dati sensibili a causa di queste vulnerabilità. L'attacco potrebbe compromettere la reputazione e la conformità normativa.

Potential operational benefits

  • Riduzione della superficie esposta alle minacce
  • Prevenzione di accessi non autorizzati a dati sensibili
  • Miglioramento della conformità normativa
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSMFA / IdentitàMonitoraggio / SIEMSegmentazione di rete
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
25/09/2026 06:46
MITRE ATT&CK
T1190, T1078
CVE
CVE-2026-5430
Classification
Critical
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source