INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Adobe and WSO2 Vulnerabilities Exploited in Attacks

| 2026-09-25 17:24 CRITICAL HIGH
Executive Summary AI-generated
The threat landscape is rapidly evolving, with hackers exploiting critical vulnerabilities in various products to compromise security. The most recent incident data reveals a targeted attack on enterprise software provider WSO2 API Manager versions 4.1.0 through 4.6.0, leveraging CVE-2026-5430 and CVE-2026-71362. These flaws have been identified by the Cybersecurity and Infrastructure Security Agency (CISA) as critical-severity bugs with maximum severity scores of 5 out of 10. The vulnerabilities are being exploited in Adobe Commerce and Magento e-commerce platforms, allowing threat actors to compromise administrative accounts and take full control. The attackers successfully exploiting these vulnerabilities could compromise sensitive data and disrupt business operations. As a result, federal agencies using the affected products have until Sunday, September 27, to apply recommended updates or mitigations, or discontinue their use.
Technical Mitigations AI-generated
* Implement secure authentication mechanisms that verify JWT signatures using the latest algorithms (e.g. RSA, ECDSA) and consider using multi-factor authentication to prevent unauthorized access. * Regularly update and patch Adobe Commerce and Magento products to ensure you have the latest security fixes and patches for known vulnerabilities like CVE-2026-71362. * Use a secure protocol such as HTTPS/SSL/TLS to encrypt communication between clients and servers, and configure firewalls to block suspicious traffic patterns. * Monitor system logs and network traffic for signs of unauthorized access or malicious activity, and take prompt action if any issues are detected.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-67279CVE-2026-67279 CVE-2026-65660CVE-2026-65660 CVE-2026-5430CVE-2026-5430 CVE-2026-71362CVE-2026-71362
Target & Sectors
FIVE_EYES FIVE_EYES BENELUX BENELUX logisticslogistics governmentgovernment technologytechnology telecommunicationstelecommunications
Incident Timeline
‎May 3
Threat actors exploited the vulnerability in Adobe and WSO2 software to compromise administrative accounts.
‎July 2026
Threat actors exploited a vulnerability in Adobe and WSO2 products to launch attacks against Commerce, Magento Open Source versions.
organisation Commerce
organisation Magento Open Source
‎August 2026
Threat actors exploited Adobe and WSO2 flaws in attacks added to the CISA catalog.
vulnerability CVE-2026-71362
organisation Sansec
infrastructure 9.1
‎September 10, 2026
Threat actors exploited a vulnerability in Adobe and WSO2 software targeting Australian honeypot sensors.
organisation IP
target_region Australia
‎September 13
Threat actors used an IP address to exploit a flaw in Adobe and WSO2 products on September 13.
organisation IP
‎September 13, 2026
Threat actors exploited vulnerabilities in Adobe and WSO2 software to launch targeted attacks against organizations.
‎at least September 13, 2026
Threat actors exploited CVE-2026-5430 vulnerabilities in Adobe and WSO2 products to launch attacks against watchTowr's honeypots.
organisation CVE-2026-5430
organisation KEV
‎September 15
Threat actors exploited known vulnerabilities in Adobe and WSO2 to launch attacks against targets.
‎September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Adobe and WSO2 vulnerabilities to its Known Exploited Vulnerabilities catalog on September 25, 2026.
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
‎Sep 25, 2026
Threat actors exploited vulnerabilities in Adobe and WSO2 software to launch targeted attacks against organizations.
‎2026/09/25
Adobe and WSO2 flaws exploited in attacks added to CISA catalog.
victims 1,000 customers
infrastructure 4.1.0
infrastructure 4.6.0
infrastructure 4.5.0
organisation The CVE-2026-5430
organisation API Control Plane
organisation Adobe Commerce
organisation KEV
organisation Adobe's Commerce
organisation Magento
organisation Sansec
organisation CVSS
organisation Microsoft SharePoint
organisation SSH
organisation Cybersecurity
organisation Adobe
organisation JWT
organisation API
organisation NFL
organisation CHANEL
‎Sunday, September 27
Threat actors exploited Adobe and WSO2 flaws in attacks targeting federal agencies.
attribution the Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎September 27
Threat actors exploited Adobe and WSO2 flaws in attacks targeting federal agencies.
‎September 27, 2026
Threat actors exploited Adobe and WSO2 flaws in attacks targeting federal agencies.
attribution FCEB
attribution Federal Civilian Executive Branch
‎Monday, September 28
The Microsoft SharePoint and Mikrotik RouterOS systems were compromised due to known vulnerabilities that will be patched by the end of Monday, September 28.
attribution the Microsoft SharePoint
attribution Mikrotik RouterOS
Tactical Metrics
Metrics
victims
1,000
Customers
Metrics
infrastructure
‎4.1.0
Software Version
Metrics
infrastructure
‎4.6.0
Software Version
Metrics
infrastructure
‎4.5.0
Software Version
Metrics
infrastructure
‎9.1
Software Version