THE US Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on 24 September 2026: CVE-2026-5430, a WSO2 multiple-products path traversal vulnerability with a CVSS score of 10.0, and CVE-2026-71362, an Adobe Commerce and Magento incorrect-authorisation vulnerability rated 9.1.
CISA’s catalog identifies vulnerabilities known to have been exploited, although the article does not provide evidence that both flaws are currently being exploited in the same campaigns.
CVE-2026-5430 is described as an authentication bypass caused by improper JWT-signature verification. An attacker can use an unsupported signing algorithm to gain unauthorised access and potentially take over accounts. CVE-2026-71362 affects Adobe Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches. It allows an unauthenticated attacker to switch customer sessions, hijack accounts and access private data without user interaction.
Sansec reported blocking initial exploitation attempts after Adobe published its advisory and said the flaw could be exploited without an account or administrator privileges. Adobe released isolated patch files in advisory APSB26-92; the update addresses seven vulnerabilities, including the account-takeover flaw. CISA requires federal agencies to remediate both vulnerabilities by 27 September 2026, while private organisations are advised to review the KEV catalog and apply the relevant fixes.