CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog

CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following active exploitation.
Table of Contents
    Add a header to begin generating the table of contents

    The Cybersecurity and Infrastructure Security Agency added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog on September 25, 2026, following confirmation of active exploitation in the wild. CVE-2026-5430, a path traversal vulnerability in WSO2 API Control Plane with a CVSS score of 9.8, and a second flaw affecting Adobe Commerce and Magento platforms are now under attack, prompting CISA to mandate federal agency remediation by a specified deadline.

    CVE-2026-5430: Path Traversal in WSO2 API Control Plane Enables Critical Compromise

    CVE-2026-5430 targets WSO2 API Control Plane, an enterprise API management platform organizations use to govern, secure, and monitor APIs across their infrastructure. The path traversal vulnerability allows attackers to access files outside the intended directory structure, potentially reading sensitive configuration files, credentials, or application code. With a CVSS score of 9.8, the flaw represents a critical-severity issue that likely requires little or no authentication and can lead to complete system compromise.

    Path traversal attacks work by manipulating file path parameters to escape restricted directories, often using sequences like ../ to navigate up the directory tree. Once an attacker can read arbitrary files, they typically target configuration files containing database credentials, API keys, or other secrets that enable lateral movement or direct data access. On API management infrastructure, successful exploitation could expose the credentials and configuration for every API the platform governs, granting attackers access to backend services across the organization.

    Adobe Commerce and Magento Flaw Expands KEV Entry to E-Commerce Infrastructure

    CISA’s KEV addition also includes a second vulnerability affecting Adobe Commerce and Magento, the widely deployed e-commerce platforms that power online storefronts for retailers worldwide. The advisory did not specify the CVE identifier, technical details, or CVSS score for the Adobe flaw, but its inclusion in the KEV catalog confirms active exploitation and critical impact on e-commerce infrastructure.

    Adobe Commerce and Magento vulnerabilities have historically been high-value targets for attackers seeking to compromise online payment processing, steal customer data, or inject malicious scripts into checkout flows. The active exploitation of an Adobe e-commerce flaw alongside the WSO2 API vulnerability suggests attackers are targeting both API infrastructure and customer-facing web platforms in coordinated campaigns.

    CISA Remediation Mandate and Federal Agency Patching Deadlines

    CISA’s KEV catalog inclusion triggers a binding operational directive requiring federal civilian agencies to patch the vulnerabilities by a specified deadline. While the directive applies only to federal agencies, CISA issues KEV additions as a signal to all organizations that the vulnerabilities are actively exploited and demand immediate attention.

    Organizations running WSO2 API Control Plane or Adobe Commerce and Magento must apply patches immediately, regardless of whether they are subject to the federal mandate. Active exploitation means attackers have working exploits and are scanning for or actively targeting vulnerable systems. Delaying patching extends the window during which an organization’s API infrastructure or e-commerce platform remains exposed to known attacks.

    Active Exploitation Patterns Targeting Enterprise API and E-Commerce Platforms

    The dual KEV addition—one API management platform, one e-commerce platform—reflects attacker focus on high-value enterprise infrastructure. API management systems serve as central control points for an organization’s entire API ecosystem, making them attractive targets for attackers seeking to compromise multiple backend services through a single entry point. E-commerce platforms store payment card data, customer records, and transaction histories, all valuable for fraud or resale.

    The active exploitation of both vulnerability types in the same timeframe suggests either a coordinated campaign targeting both enterprise and e-commerce sectors or independent attacker groups opportunistically exploiting whatever high-severity flaws emerge. Either way, the pattern underscores the need for organizations to treat any critical vulnerability in API or payment infrastructure as an urgent remediation priority, particularly once CISA confirms in-the-wild exploitation.

    CISA does not disclose which threat actors are exploiting KEV-listed vulnerabilities or what their objectives are, leaving organizations to assume any exploitation could serve espionage, ransomware deployment, data theft, or financial fraud. The lack of attribution detail means defenders cannot tailor their response based on adversary capabilities—they must assume sophisticated, well-resourced attackers and patch accordingly.

    Related Posts