ON 24 September 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities affecting WSO2 products and Adobe Commerce to its Known Exploited Vulnerabilities (KEV) catalogue. The agency’s listing indicates that both flaws are being exploited, although the supplied report does not provide details of the attacks.
CVE-2026-5430 has a CVSS score of 10.0 and affects WSO2 API Manager versions 4.1.0 to 4.6.0, as well as API Control Plane, Traffic Manager and Universal Gateway versions 4.5.0 and 4.6.0. CVE-2026-71362, rated 9.1, affects Adobe Commerce and Magento Open Source versions 2.4.4 to 2.4.9 where the August 2026 security updates have not been installed.
The report says CVE-2026-5430 results from defective JSON Web Token verification. An unauthenticated attacker can submit a token using an unsupported signing algorithm, which the server may accept and use to bypass authentication. CVE-2026-71362 is described as an authorisation flaw that can allow access to restricted resources without user interaction. No public proof-of-concept code has reportedly been observed, but internet-facing unpatched systems are described as at risk of account takeover.
Administrators should apply the relevant WSO2 fixes or product updates and install Adobe’s August 2026 security releases. The report says US federal civilian agencies must remediate both vulnerabilities by 27 September 2026.