Vulnerabilities in this CISA update: 4 (Source: BleepingComputer, reporting on CISA KEV additions)
The Cybersecurity and Infrastructure Security Agency (CISA) has added two critical-severity vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, BleepingComputer reported. One is CVE-2026-5430, an authentication bypass in multiple WSO2 products. The other is CVE-2026-71362, an incorrect authorization flaw in Adobe Commerce and Magento. Two further flaws are also being exploited: CVE-2026-65660, a high-severity code injection flaw in Microsoft SharePoint, and CVE-2026-67279, a medium-severity pre-authentication bypass in Mikrotik RouterOS.
For the two critical issues, federal agencies have until Sunday, September 27 to apply updates or mitigations, or to discontinue use. The SharePoint and RouterOS deadline is Monday, September 28. Those dates bind federal agencies. CISA also encourages all organizations to prioritize the issues listed in the KEV.
WSO2: a forged token was enough in testing
CVE-2026-5430 received a maximum severity score. It affects WSO2 API Manager versions 4.1.0 through 4.6.0, plus API Control Plane, Traffic Manager and Universal Gateway versions 4.5.0 and 4.6.0. The cause is the JWT authentication mechanism accepting tokens signed with an unsupported algorithm. In its original May 3 advisory, the vendor said a successful attacker could compromise administrative accounts and take full control.
CISA has not shared details about the attacks. Security firm watchTowr said on September 15 that its honeypots captured exploitation attempts. The researchers observed a limited number of attempts from one IP address on September 13, using forged JWT tokens. That attacker targeted the wrong WSO2 product for this CVE. watchTowr then reproduced the attack on the correct product, where a forged token could expose API endpoints and application credentials.
watchTowr threat intelligence specialist Yordan Ganchev told BleepingComputer that WSO2 is not a niche target. "Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics," he said. He added: "Organizations in these sectors can't afford to wait for exploitation to be formally confirmed."
Adobe Commerce: no account required
CVE-2026-71362 affects Adobe's Commerce and Magento e-commerce platforms. E-commerce security company Sansec observed it being exploited in the wild. Sansec said threat actors require "no existing account, administrator privileges, or user interaction" to use it. For a retailer, that means the flaw is reachable without any credential the organisation issued.
What this means for the budget
The WSO2 sequence is specific and documented, though narrow. The vendor published its advisory on May 3. watchTowr recorded forged-token attempts from one IP address on September 13. CISA's listing followed. Those attempts hit the wrong product, and watchTowr's reproduction on the correct one showed credential exposure. Organisations running affected WSO2 versions that waited for a KEV entry would have left the gateway exposed through the interval between advisory and listing. The source does not say when a fix became available relative to the May 3 advisory, so the length of that exposure depends on each organisation's version and patch options.
The four products span an API gateway, a commerce platform, a collaboration server and a network router. Do you know who owns each one inside your organisation?
Questions for your team this week
1. Do we run WSO2 API Manager 4.1.0 through 4.6.0, or the 4.5.0 and 4.6.0 components named above? If so, which are internet-facing, and has each been updated or mitigated?
2. For any exposed WSO2 instance, have we reviewed logs for forged JWT tokens back to the May 3 advisory date, or to the earliest retention we hold? September 13 is only the first documented attempt, not a confirmed start of exploitation. Have we also rotated the application credentials and API keys stored behind the instance?
3. Do we operate Adobe Commerce or Magento, and has CVE-2026-71362 been addressed? Who owns that decision, our team or an agency?
4. Do we have SharePoint (CVE-2026-65660) or RouterOS (CVE-2026-67279) in scope, and are we tracking the September 28 federal date as a benchmark for our own timeline?
5. When a vendor advisory names a maximum-severity authentication flaw, what is our stated time to patch, and is it tied to the advisory date rather than to a KEV listing?





