INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Adobe and WSO2 Vulnerabilities Exploited in Attacks
| 2026-09-25 17:24 CRITICAL HIGHExecutive Summary AI-generated
The threat landscape is rapidly evolving, with hackers exploiting critical vulnerabilities in various products to compromise security. The most recent incident data reveals a targeted attack on enterprise software provider WSO2 API Manager versions 4.1.0 through 4.6.0, leveraging CVE-2026-5430 and CVE-2026-71362. These flaws have been identified by the Cybersecurity and Infrastructure Security Agency (CISA) as critical-severity bugs with maximum severity scores of 5 out of 10. The vulnerabilities are being exploited in Adobe Commerce and Magento e-commerce platforms, allowing threat actors to compromise administrative accounts and take full control. The attackers successfully exploiting these vulnerabilities could compromise sensitive data and disrupt business operations. As a result, federal agencies using the affected products have until Sunday, September 27, to apply recommended updates or mitigations, or discontinue their use.
Technical Mitigations AI-generated
* Implement secure authentication mechanisms that verify JWT signatures using the latest algorithms (e.g. RSA, ECDSA) and consider using multi-factor authentication to prevent unauthorized access.
* Regularly update and patch Adobe Commerce and Magento products to ensure you have the latest security fixes and patches for known vulnerabilities like CVE-2026-71362.
* Use a secure protocol such as HTTPS/SSL/TLS to encrypt communication between clients and servers, and configure firewalls to block suspicious traffic patterns.
* Monitor system logs and network traffic for signs of unauthorized access or malicious activity, and take prompt action if any issues are detected.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-67279CVE-2026-67279
CVE-2026-65660CVE-2026-65660
CVE-2026-5430CVE-2026-5430
CVE-2026-71362CVE-2026-71362
Target & Sectors
FIVE_EYES
FIVE_EYES
BENELUX
BENELUX
logisticslogistics
governmentgovernment
technologytechnology
telecommunicationstelecommunications
Incident Timeline
May 3
Threat actors exploited the vulnerability in Adobe and WSO2 software to compromise administrative accounts.
July 2026
Threat actors exploited a vulnerability in Adobe and WSO2 products to launch attacks against Commerce, Magento Open Source versions.
Click on any entity below to view its context and source!
organisation
Commerce
The flaw affects Commerce, Commerce B2B and Magento Open Source versions through the
July 2026 patches
.
organisation
Magento Open Source
The flaw affects Commerce, Commerce B2B and Magento Open Source versions through the
July 2026 patches
.
August 2026
Threat actors exploited Adobe and WSO2 flaws in attacks added to the CISA catalog.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-71362
In August 2026, hackers
began targeting
CVE-2026-71362 shortly after
its public disclosure
.
As for
CVE-2026-71362
, Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw.
organisation
Sansec
As for
CVE-2026-71362
, Sansec noted in August 2026 that it had detected and blocked exploitation attempts aimed at the flaw.
infrastructure
9.1
The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9.1.
September 10, 2026
Threat actors exploited a vulnerability in Adobe and WSO2 software targeting Australian honeypot sensors.
Click on any entity below to view its context and source!
organisation
IP
"
Previdian's telemetry
indicates
that a lone IP address from Australia attempted to exploit the flaw targeting its honeypot sensors on September 10, 2026.
target_region
Australia
"
Previdian's telemetry
indicates
that a lone IP address from Australia attempted to exploit the flaw targeting its honeypot sensors on September 10, 2026.
September 13
Threat actors used an IP address to exploit a flaw in Adobe and WSO2 products on September 13.
Click on any entity below to view its context and source!
organisation
IP
The researchers said they observed a limited number of attempts from one IP address on September 13 using forged JWT tokens against a WSO2 product.
September 13, 2026
Threat actors exploited vulnerabilities in Adobe and WSO2 software to launch targeted attacks against organizations.
at least September 13, 2026
Threat actors exploited CVE-2026-5430 vulnerabilities in Adobe and WSO2 products to launch attacks against watchTowr's honeypots.
Click on any entity below to view its context and source!
organisation
CVE-2026-5430
The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026.
organisation
KEV
The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026.
September 15
Threat actors exploited known vulnerabilities in Adobe and WSO2 to launch attacks against targets.
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Adobe and WSO2 vulnerabilities to its Known Exploited Vulnerabilities catalog on September 25, 2026.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog.
attribution
Known Exploited
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 25, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog.
Sep 25, 2026
Threat actors exploited vulnerabilities in Adobe and WSO2 software to launch targeted attacks against organizations.
2026/09/25
Adobe and WSO2 flaws exploited in attacks added to CISA catalog.
Click on any entity below to view its context and source!
victims
1,000 customers
“Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics,” explained Ganchev.
infrastructure
4.1.0
The CVE-2026-5430 flaw received a
maximum severity score
and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
infrastructure
4.6.0
The CVE-2026-5430 flaw received a
maximum severity score
and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
infrastructure
4.5.0
The CVE-2026-5430 flaw received a
maximum severity score
and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
organisation
The CVE-2026-5430
The CVE-2026-5430 flaw received a
maximum severity score
and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
organisation
API Control Plane
The CVE-2026-5430 flaw received a
maximum severity score
and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
organisation
Adobe Commerce
The agency also added CVE-2026-71362, another critical-severity flaw affecting Adobe Commerce, to the list of security issues being leveraged in attacks.
The second flaw added to the catalog, tracked as
CVE-2026-71362
(CVSS score 9.1), is an incorrect authorization vulnerability in Adobe Commerce that can allow an unauthenticated attacker to escalate privileges and gain access to sensitive resources without user interaction.
An incorrect authorization vulnerability in Adobe Commerce and Magento that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
organisation
KEV
The second critical-severity bug added to the KEV is CVE-2026-71362, an incorrect authorization vulnerability in Adobe's Commerce and Magento e-commerce platforms.
organisation
Adobe's Commerce
The second critical-severity bug added to the KEV is CVE-2026-71362, an incorrect authorization vulnerability in Adobe's Commerce and Magento e-commerce platforms.
organisation
Magento
The second critical-severity bug added to the KEV is CVE-2026-71362, an incorrect authorization vulnerability in Adobe's Commerce and Magento e-commerce platforms.
An incorrect authorization vulnerability in Adobe Commerce and Magento that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
Adobe fixed how Magento handles customer identity in account sessions.
organisation
Sansec
Ecommerce security company
Sansec observed
CVE-2026-71362 being exploited in the wild, saying that threat actors require "no existing account, administrator privileges, or user interaction" to leverage it.
Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory.
organisation
CVSS
The second flaw added to the catalog, tracked as
CVE-2026-71362
(CVSS score 9.1), is an incorrect authorization vulnerability in Adobe Commerce that can allow an unauthenticated attacker to escalate privileges and gain access to sensitive resources without user interaction.
organisation
Microsoft SharePoint
Hackers are also exploiting two additional vulnerabilities: a high-severity code injection flaw in Microsoft SharePoint tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS identified as CVE-2026-67279.
organisation
SSH
Hackers are also exploiting two additional vulnerabilities: a high-severity code injection flaw in Microsoft SharePoint tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS identified as CVE-2026-67279.
organisation
Cybersecurity
Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory.
organisation
Adobe
Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory.
organisation
JWT
The problem stems from the JWT authentication mechanism accepting tokens signed with an unsupported algorithm.
organisation
API
watchTowr reproduced the attack on the correct product, where a forged token could expose API endpoints and application credentials.
A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remote code execution.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Sunday, September 27
Threat actors exploited Adobe and WSO2 flaws in attacks targeting federal agencies.
Click on any entity below to view its context and source!
attribution
the Known Exploited
For the two critical issues added to the Known Exploited Vulnerabilities (
KEV
) catalog, federal agencies using the affected products have until Sunday, September 27, to apply the recommended updates or mitigations, or discontinue their use.
tactic
T1588.006 - Vulnerabilities
For the two critical issues added to the Known Exploited Vulnerabilities (
KEV
) catalog, federal agencies using the affected products have until Sunday, September 27, to apply the recommended updates or mitigations, or discontinue their use.
attribution
KEV
For the two critical issues added to the Known Exploited Vulnerabilities (
KEV
) catalog, federal agencies using the affected products have until Sunday, September 27, to apply the recommended updates or mitigations, or discontinue their use.
September 27
Threat actors exploited Adobe and WSO2 flaws in attacks targeting federal agencies.
September 27, 2026
Threat actors exploited Adobe and WSO2 flaws in attacks targeting federal agencies.
Click on any entity below to view its context and source!
attribution
FCEB
Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats.
attribution
Federal Civilian Executive Branch
Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for both vulnerabilities by September 27, 2026, to safeguard their networks against active threats.
Monday, September 28
The Microsoft SharePoint and Mikrotik RouterOS systems were compromised due to known vulnerabilities that will be patched by the end of Monday, September 28.
Click on any entity below to view its context and source!
attribution
the Microsoft SharePoint
For the Microsoft SharePoint and Mikrotik RouterOS flaws, CISA is giving agencies until Monday, September 28 to fix them.
attribution
Mikrotik RouterOS
For the Microsoft SharePoint and Mikrotik RouterOS flaws, CISA is giving agencies until Monday, September 28 to fix them.
Tactical Metrics
Metrics
victims
1,000
Customers
Click for context!
“Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics,” explained Ganchev.
Metrics
infrastructure
4.1.0
Software Version
The CVE-2026-5430 flaw received a
maximum severity score
and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
Metrics
infrastructure
4.6.0
Software Version
The CVE-2026-5430 flaw received a
maximum severity score
and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
Metrics
infrastructure
4.5.0
Software Version
The CVE-2026-5430 flaw received a
maximum severity score
and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
Metrics
infrastructure
9.1
Software Version
The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9.1.
Intelligence Sources
Security Affairs
2026-09-25
The Hacker News
2026-09-25
BleepingComputer
2026-09-25
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-26T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
attribution
Attributing Entity
The Cybersecurity and Infrastructure Security Agency
authority
20x
organisation
Identified Entity
Adobe Commerce
entity
17x
timeline
Temporal Reference
4.6.0
date
4x
industry
Targeted Sector
Technology
sector
4x
vulnerability
Exploited CVE
CVE-2026-5430
cve
4x
infrastructure
Software Version
4.1.0
version
2x
tactic
MITRE ATT&CK Technique
T1213.002 - Sharepoint
technique
2x
vulnerability
CVSS Score
10
score
2x
target region
Target Country
Australia
country
Contextual Telemetry
Context Block
6 METRICS
victims
Customers
1,000
customers
general metric
Cvss Score
9
cvss score
general metric
Apsb26
92
apsb26
general metric
Vulnerabilities
10
vulnerabilities
tactic
Cyber Operation Type
Remote Code Execution
tactic
general metric
Sep
25
sep
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.