CISA Warns SharePoint, WSO2, Adobe Flaws Exploited
The Cybersecurity and Infrastructure Security Agency has updated its catalog to include actively exploited flaws affecting enterprise software from WSO2, Adobe Commerce, Microsoft, and Mikrotik.

CISA Expands Known Exploited Vulnerabilities Catalog
The Cybersecurity and Infrastructure Security Agency has issued urgent warnings regarding multiple vulnerabilities actively being leveraged in attacks against enterprise products. As detailed in a report by [BleepingComputer](https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/), the agency added several critical and high-severity security issues to its [KEV](http://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog) catalog, ordering federal agencies to remediate the flaws within strict deadlines.
The newly flagged vulnerabilities impact software from WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS. Federal agencies utilizing the affected products have been instructed to apply recommended updates or mitigations, or discontinue use entirely, before the imposed deadlines.
WSO2 Authentication Bypass Vulnerability
At the center of CISA's latest warnings is a critical authentication bypass flaw tracked as CVE-2026-5430. This security issue received a [maximum severity score](http://nvd.nist.gov/vuln/detail/cve-2026-5430) and affects multiple products from enterprise software provider WSO2, including API Manager versions 4.1.0 through 4.6.0, as well as API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.
The underlying problem stems from the JWT authentication mechanism accepting tokens signed with an unsupported algorithm. According to the [original advisory on May 3](http://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/), a successful exploitation could allow an attacker to compromise administrative accounts and take full control of the system.
Observations From Security Researchers
While CISA has not disclosed specific details regarding the attacks, security firm [watchTowr announced](http://x.com/inkmoro/status/2099925214339727646) that its honeypots captured exploitation attempts on September 13. Researchers observed a limited number of forged JWT token attempts from a single IP address, though the initial target was incorrect.
The researchers successfully reproduced the attack on the correct product, demonstrating that a forged token could expose API endpoints and application credentials. Yordan Ganchev, a threat intelligence specialist at watchTowr, emphasized that WSO2 software is deployed across critical industries, noting that organizations in banking, government, telecommunications, and logistics cannot afford to wait for formal confirmation of exploitation.
Adobe Commerce and Other Flaws Added to Catalog
In addition to the WSO2 flaw, CISA added CVE-2026-71362, an incorrect authorization vulnerability affecting Adobe's Commerce and Magento e-commerce platforms, to the KEV catalog. E-commerce security company [Sansec observed](https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-adobe-commerce-flaw-to-hijack-customer-accounts/) the vulnerability being exploited in the wild, pointing out that threat actors require no existing account, administrator privileges, or user interaction to leverage the issue.
Hackers are also actively exploiting two additional vulnerabilities: a high-severity code injection flaw in Microsoft SharePoint tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine workflow bypass in Mikrotik RouterOS identified as CVE-2026-67279.
Remediation Deadlines for Federal Agencies
Federal civilian executive branch agencies have been given strict timeframes to secure their environments against these active threats. For the two critical issues added to the KEV catalog—WSO2 and Adobe Commerce—agencies must apply the recommended updates, mitigations, or discontinue product use by Sunday, September 27.
For the Microsoft SharePoint and Mikrotik RouterOS vulnerabilities, CISA has established a separate deadline, requiring agencies to implement fixes by Monday, September 28. CISA continues to encourage all organizations outside the federal civilian executive branch to prioritize addressing these security issues promptly.
Sources
- BleepingComputerCISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks