CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider W
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
Bill Toulas
- September 25, 2026
- 01:24 PM

The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.
The agency also addedΒ CVE-2026-71362, another critical-severity flaw affecting Adobe Commerce, to the list of security issues being leveraged in attacks.
Hackers are also exploiting two additional vulnerabilities: a high-severity code injection flaw in Microsoft SharePoint tracked asΒ CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine/workflow bypassΒ in Mikrotik RouterOS identified as CVE-2026-67279.
For the two critical issues added to the Known Exploited Vulnerabilities (KEV) catalog, federal agencies using the affected products have untilΒ Sunday, September 27, to apply the recommended updates or mitigations, or discontinue their use.
The CVE-2026-5430 flaw received a maximum severity score and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
In the original advisory on May 3, the vendor says that an attacker successfully exploiting the vulnerability could compromise administrative accounts and take full control.
The problem stems from the JWT authentication mechanism accepting tokens signed with an unsupported algorithm.
CISA has not shared any details about the attacks, but security firm watchTowr announced on September 15 announced that its honeypots captured exploitation attempts.
The researchers said they observed a limited number of attempts from one IP address on September 13 using forged JWT tokens against a WSO2 product. However, the attacker targeted the wrong product for CVE-2026-5430.
watchTowr reproduced the attack on the correct product, where a forged token could expose API endpoints and application credentials.
Yordan Ganchev, threat intelligence specialist at watchTowr, told BleepingComputer that WSO2 is not a niche target.
βIts technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics,β explained Ganchev.
βOrganizations in these sectors can't afford to wait for exploitation to be formally confirmed.β
The second critical-severity bug added to the KEV is CVE-2026-71362, an incorrect authorization vulnerability in Adobe's Commerce and Magento e-commerce platforms.
Ecommerce security company Sansec observed CVE-2026-71362 being exploited in the wild, saying that threat actors require "no existing account, administrator privileges, or user interaction" to leverage it.
The deadline for federal agencies to mitigate both vulnerabilities is September 27, but CISA encourages all organizations to take action and prioritize addressing the security issues listed in the KEV.
For the Microsoft SharePoint and Mikrotik RouterOS flaws, CISA is giving agencies until Monday, September 28 to fix them.
Build your security blueprint for AI-powered attacks
Join Mikko HyppΓΆnen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seatOriginally published by BleepingComputer. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.