WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
Summary
CISA has added two critical vulnerabilities, one in WSO2 API Control Plane and another in Adobe Commerce and Magento, to its Known Exploited Vulnerabilities (KEV) catalog. These additions are based on evidence that both flaws are currently being actively exploited in the wild.
IFF Assessment
The inclusion of actively exploited vulnerabilities in the KEV catalog indicates a significant risk to organizations and potential for successful attacks against them.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 27, 2026. Known ransomware use: Unknown.
Defender Context
Defenders must prioritize patching or implementing mitigations for the WSO2 API Control Plane and Adobe Commerce/Magento vulnerabilities listed in the CISA KEV catalog. Active exploitation means these flaws are currently being leveraged by attackers, posing an immediate threat to systems running the affected software.