CISA Adds Two Known Exploited Vulnerabilities to Catalog

Summary

CISA has added two new vulnerabilities, CVE-2026-5430 (WSO2 Path Traversal) and CVE-2026-71362 (Adobe Commerce/Magento Incorrect Authorization), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This action reinforces CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize the remediation of these high-risk vulnerabilities on publicly exposed assets.

IFF Assessment

FOE

The addition of new, actively exploited vulnerabilities to CISA's KEV Catalog indicates new threats that defenders must address, posing a risk to organizations.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 27, 2026. Known ransomware use: Unknown.

Defender Context

Organizations, particularly federal agencies, must closely monitor CISA's KEV Catalog for newly added vulnerabilities and prioritize patching them. The inclusion of these vulnerabilities highlights common attack vectors like path traversal and authorization bypass, which are frequently leveraged by threat actors.

Read Full Story →