Search
Find merged stories by title or summary.
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability • CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products caused by improper verification of JWT signatures, allowing an attacker to use an unsupported signing algorithm to gain unauthorized access and potentially take over accounts. The second flaw added to the catalog, tracked as CVE-2026-71362 (CVSS score 9.
[Previdian] CVE-2026-71362 - Confirmed Exploitation
CVE-2026-71362 Catalog: Previdian Status: Confirmed Exploited: Yes Status Updated: 2026-09-10 06:31 UTC Evidence Sources: 1 First Seen: 2026-09-10 Asserted: 2026-09-10
Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild macOS Screen Sharing Flaw Exploited to Deploy Monero Miners GeoServer Zero-Day Is Already Being Probed. That’s the Problem Apple warned hundreds of users of mercenary spyware attacks AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers Chess. com Leak Exposes 7. 3 Million Users – Evidence Points to Scraping US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure U. S.
Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure
Hackers began targeting a critical Adobe Commerce flaw that could let unauthenticated attackers hijack customer accounts and access private data. Hackers began targeting CVE-2026-71362 (CVSS score of 9. 1), a critical Adobe Commerce flaw, shortly after its public disclosure . The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data. Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory. The flaw affects Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches . Adobe released an isolated fix and urged users to patch. “Adobe has released APSB26-92 as isolated patch files. The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9. 1. Sansec Shield already blocks exploitation attempts.”
Adobe Commerce Bug Targeted Immediately After Disclosure
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek .
Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code
Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, fixing several vulnerabilities that could allow attackers to bypass security controls, gain higher privileges, and execute arbitrary code. The most serious issue is CVE-2026-71362, an incorrect authorization vulnerability rated 9. 1 out of 10 under the CVSS scoring system. The flaw could allow an unauthenticated remote attacker to escalate privileges without requiring administrator access. Adobe classified the vulnerability as critical because it could expose sensitive data and allow attackers to make unauthorized changes within affected commerce environments. Adobe Commerce Vulnerabilities Adobe also addressed two critical stored cross-site scripting vulnerabilities, CVE-2026-48414 and CVE-2026-48413. Both flaws may result in arbitrary code execution when exploited successfully.
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [... ]
You've reached the end of current stories for this search.
