CISA Flags Actively Exploited WSO2 and Adobe Commerce Vulnerabilities

CISA added two critical vulnerabilities affecting WSO2 and Adobe Commerce/Magento to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. One of them, CVE-2026-5430, is a path traversal issue in WSO2 API Control Plane with a 9.8 severity score.
CISA has added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog. The affected products are WSO2 and Adobe Commerce/Magento. The catalog entry follows evidence that these flaws are being actively exploited.
One vulnerability, CVE-2026-5430, is a path traversal issue in WSO2 API Control Plane. It has a severity score of 9.8. The summary does not provide further details about the second flaw.
Organizations running WSO2 API Control Plane or Adobe Commerce/Magento may face heightened risk if these flaws remain unpatched. Because active exploitation is reported, attackers could potentially disrupt services, access sensitive data, or compromise systems. Customers, employees, and partners of affected businesses could be indirectly affected. The 9.8 severity score suggests the WSO2 issue may be especially serious, though real-world harm depends on exposure, mitigation, and response.