CuraSec

Act active

WSO2 and Adobe Commerce Flaws Actively Exploited, Added to CISA KEV

2026-09-25 15:49 UTC · The Hacker News · read the source ↗ #cisa-kev#wso2#adobe-commerce
  • Engineer — Act: Both flaws are CISA KEV-listed with confirmed active exploitation; patch WSO2 API Control Plane (CVE-2026-5430, CVSS 9.8) and Adobe Commerce/Magento immediately — a public PoC is on GitHub, lowering the bar for opportunistic exploitation.
  • SOC/IR — Act: KEV listing confirms in-the-wild exploitation of both products; sweep web and API gateway logs for path traversal patterns targeting WSO2 API Control Plane and audit Adobe Commerce instances for webshell drops or unauthorized file access since the PoC became public.
  • Leader — Plan: Confirm whether WSO2 API Control Plane or Adobe Commerce is in your environment and direct engineering to treat these as this-week patches; Adobe Commerce’s payment-processing role adds PCI DSS urgency if applicable.
  • Signals: CVE-2026-5430 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.