CISA Adds Two Known Exploited Vulnerabilities to Catalog
Summary
CISA has added two new vulnerabilities, CVE-2026-5430 (WSO2 Path Traversal) and CVE-2026-71362 (Adobe Commerce/Magento Incorrect Authorization), to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This action reinforces CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize the remediation of these high-risk vulnerabilities on publicly exposed assets.
IFF Assessment
The addition of new, actively exploited vulnerabilities to CISA's KEV Catalog indicates new threats that defenders must address, posing a risk to organizations.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 27, 2026. Known ransomware use: Unknown.
Defender Context
Organizations, particularly federal agencies, must closely monitor CISA's KEV Catalog for newly added vulnerabilities and prioritize patching them. The inclusion of these vulnerabilities highlights common attack vectors like path traversal and authorization bypass, which are frequently leveraged by threat actors.