U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
Brief
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog.
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog :
- CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability
- CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability
The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products caused by improper verification of JWT signatures, allowing an attacker to use an unsupported signing algorithm to gain unauthorized access and potentially take over accounts.
The second flaw added to the catalog, tracked as CVE-2026-71362 (CVSS score 9.
