WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

Summary

CISA has added two critical vulnerabilities, one in WSO2 API Control Plane and another in Adobe Commerce and Magento, to its Known Exploited Vulnerabilities (KEV) catalog. These additions are based on evidence that both flaws are currently being actively exploited in the wild.

IFF Assessment

FOE

The inclusion of actively exploited vulnerabilities in the KEV catalog indicates a significant risk to organizations and potential for successful attacks against them.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 27, 2026. Known ransomware use: Unknown.

Defender Context

Defenders must prioritize patching or implementing mitigations for the WSO2 API Control Plane and Adobe Commerce/Magento vulnerabilities listed in the CISA KEV catalog. Active exploitation means these flaws are currently being leveraged by attackers, posing an immediate threat to systems running the affected software.

Read Full Story →