← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 25, 2026 · 08:22via Security Affairs

U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

Brief

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog.

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog :

  • CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
  • CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability

The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products caused by improper verification of JWT signatures, allowing an attacker to use an unsupported signing algorithm to gain unauthorized access and potentially take over accounts.

The second flaw added to the catalog, tracked as CVE-2026-71362 (CVSS score 9.

Read more on Security Affairs→