MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-25 · via BleepingComputer

CISA flags active exploitation of WSO2, Adobe Commerce, SharePoint, Mikrotik flaws

Image via BleepingComputer
Image via BleepingComputer

CISA added critical WSO2 authentication bypass CVE-2026-5430 and Adobe Commerce CVE-2026-71362 to its known exploited vulnerabilities catalog, warning of active attacks. It also noted exploitation of Microsoft SharePoint CVE-2026-65660 and Mikrotik RouterOS CVE-2026-67279. Federal agencies using affected products have until September 27 to update, mitigate, or stop using them.

Expanded Detail

CISA's catalog addition covers a maximum-severity WSO2 authentication bypass that lets forged JWT tokens signed with an unsupported algorithm compromise admin access. Affected WSO2 products include API Manager 4.1.0–4.6.0, API Control Plane, Traffic Manager, and Universal Gateway 4.5.0/4.6.0. The vendor advisory dates to May 3.

watchTowr reported honeypot activity on September 13 and reproduced the attack, showing exposed API endpoints and application credentials. Its analyst noted WSO2 serves nearly 1,000 customers in banking, government, telecom, and logistics. Adobe Commerce/Magento CVE-2026-71362, an incorrect authorization flaw, was seen exploited by Sansec without requiring accounts, admin rights, or user action.

Count? First para: CISA's(1) catalog2 addition3 covers4 a5 maximum-severity6 WSO2 7 authentication8 bypass9 that10 lets11 forged12 JWT13 tokens14 signed15 with16 an17 unsupported18 algorithm19 compromise20 admin21 access22. Affected23 WSO2 24 products25 include26 API27 Manager28 4.1.0–4.6.0,29 API30 Control31 Plane,32 Traffic33 Manager,34 and35 Universal36 Gateway37 4.5.0/4.6.0.38 The39 vendor40 advisory41 dates42 to43 May44 3.45. Second: watchTowr46 reported47 honeypot48 activity49 on50 September51 13 52 and53 reproduced54 the55 attack,56 showing57 exposed58 API59 endpoints60 and61 application62 credentials63. Its64 analyst65 noted66 WSO2 67 serves68 nearly69 1,00070 customers71 in72 banking,73 government,74 telecom,75 and76 logistics77. Adobe78 Commerce/Mag

Context

The affected products sit in government, banking, telecom, logistics, and e-commerce environments, so successful exploitation could expose sensitive data, enable account takeover, or disrupt online services. Federal deadlines may push agencies to patch, mitigate, or retire vulnerable systems quickly. For the wider public, compromised commerce platforms or API gateways may lead to fraud, service outages, or downstream security risks, though confirmed societal impact remains unclear. Count: The1 affected2 products3 sit4 in5 government,6 banking,7 telecom,8 logistics,9 and10 e-commerce11 environments,12 so13 successful14 exploitation15 could16 expose17 sensitive18 data,19 enable20 account21 takeover,22 or23 disrupt24 online25 services26. Federal27 deadlines28 may29 push30 agencies31 to32 patch,33 mitigate,34 or35 retire36 vulnerable37 systems38 quickly39. For40 the41 wider42 public,43 compromised44 commerce45 platforms46 or47 API48 gateways49 may50 lead51 to52 fraud,53 service54 outages,

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
CISA Flags Actively Exploited WSO2 and Adobe Commerce Vulnerabilities · Cybersecurity
CISA flags active exploits in SharePoint and MikroTik RouterOS · Cybersecurity
September 22 OT Security and Regulatory Update · Cybersecurity
ServiceNow Releases Fixes for Five AI Platform Vulnerabilities · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks.” Browse more stories.