CuraSec

Act active

CISA KEV: SharePoint, WSO2, Adobe Commerce Flaws Actively Exploited

  • Engineer — Act: CISA KEV listing plus public GitHub PoC confirm active exploitation of CVE-2026-5430 (WSO2 auth bypass); patch all affected WSO2 products immediately and audit authentication logs for anomalous bypass activity since PoC is publicly available.
  • SOC/IR — Act: Active exploitation confirmed via CISA KEV across WSO2, SharePoint, and Adobe Commerce; hunt for authentication bypass patterns in logs for these platforms and sweep for any anomalous sessions or privilege escalations tied to these products since the PoC went public.
  • Leader — Act: CISA-confirmed active exploitation of multiple widely-deployed enterprise platforms (SharePoint, WSO2, Adobe Commerce) warrants an immediate internal exposure check; confirm which products are in the estate and ensure patching teams treat these as P1 this week.
  • Signals: CVE-2026-5430 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.