#KEVCatalog
CISA Adds Actively Exploited WSO2 and Adobe Commerce Flaws to KEV Catalog #AdobeCommerce #CISA #KEVCatalog
CISA Adds Actively Exploited WSO2 and Adobe Commerce Flaws to KEV Catalog
 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities affecting WSO2 and Adobe Commerce to its Known Exploited Vulnerabilities (KEV) catalog, citing clear evidence of active exploitation. These flaws, tracked as CVE-2026-5430 and CVE-2026-71362, carry CVSS scores of 9.8 and 9.1 respectively, and pose severe risks to enterprises relying on these platforms for API management and e-commerce operations.  CVE-2026-5430 is a path traversal vulnerability impacting WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. It enables unauthenticated attackers to upload arbitrary files and achieve remote code execution without user interaction. Security firm watchTowr reported observing in-the-wild exploitation since at least September 13, 2026, including forged JWT tokens targeting the flaw. Yordan Ganchev, a principal threat intelligence specialist at watchTowr, emphasized that WSO2 serves nearly 1,000 customers across banking, government, telecom, and logistics—sectors that cannot afford delayed patching.  The second flaw, CVE-2026-71362, affects Adobe Commerce and Magento through an incorrect authorization bug that allows attackers to hijack customer sessions and switch accounts without interaction. This grants unauthorized access to private customer data and sensitive resources. Dutch e-commerce security company Sansec detected and blocked exploitation attempts in August 2026, while Previdian telemetry recorded a lone Australian IP targeting honeypots on September 10, 2026. Although Adobe has not yet confirmed active exploitation in its advisory, the evidence strongly suggests coordinated abuse of this vulnerability.  CISA’s inclusion of both flaws in the KEV catalog triggers mandatory remediation timelines for Federal Civilian Executive Branch (FCEB) agencies, which must apply patches by September 27, 2026. This deadline underscores the urgency for all organizations using WSO2 or Adobe Commerce to prioritize updates immediately. With threat actors already weaponizing these vulnerabilities, waiting for formal advisories or public proof-of-concept code could leave networks exposed to data theft, account takeover, and full system compromise.  Organizations should audit their deployments of WSO2 and Adobe Commerce without delay, ensuring all systems are patched to the latest secure versions. For WSO2, this means updating API Manager and related components to close the path traversal vector. Adobe Commerce and Magento users must apply authorization fixes to prevent session hijacking. Given the high CVSS scores, broad industry usage, and confirmed exploitation, treating these vulnerabilities as critical priorities is essential to safeguarding digital infrastructure and customer data from escalating cyber threats.
dlvr.it
September 26, 2026 at 1:46 PM
📰 CISA Instruksikan Penambalan Darurat Kerentanan Kritis Zimbra yang Aktif Dieksploitasi

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/08/25/cisa-instruksikan-penambalan-darurat-kerentanan-kritis-zimbra/

#cisa #cve-2026-73570 #keamananSiber #kerentananKritis #kevCatalog #patchKe
August 25, 2026 at 9:32 AM
📰 CISA Perintahkan Agen Pemerintah AS Tambal Celah Keamanan Kritis dalam 3 Hari

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/06/11/cisa-perintahkan-patching-celah-keamanan-3-hari/

#bod
26#bod26isa #cisae#hackera#keamananSibera#kevCatalogu#komputerh#patchr#pemerintahAso#teknologi#vuln
June 11, 2026 at 1:21 PM
CISA's BOD 26-04 directs federal agencies to patch based on four urgency factors: public exposure, exploit automation, takeover potential, and active exploitation. Critical flaws may require fixes in as little as 3 days. #CISA #BOD2604 #KEVCatalog
CISA directive orders agencies to prioritize vulnerability patching in a new way
CISA has directed federal agencies to prioritize patching based on four urgency criteria, including public exposure, exploit automation, system takeover potential, and active real-world exploitation. The new BOD 26-04 aims to speed remediation for the most critical vulnerabilities, with some fixes required in as little as three days and broader policy updates due over the next 180 days. #CISA #BOD26-04 #KEVCatalog
www.hendryadrian.com
June 10, 2026 at 5:45 PM
CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active Exploitation

https://cybersonar.org/go/MU5e7V
Posted at 05:33

#CybersecurityMatters #VulnerabilityManagement #KEVcatalog
February 28, 2025 at 7:20 AM
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Release Date February 18, 2026

CVE-2021-22175 GitLab Server-Side Request Forgery (SSRF) Vulnerability
CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA
CISA has added two new vulnerabilities to its KEVCatalog, based on evidence of active exploitation.
www.cisa.gov
February 22, 2026 at 3:54 AM
CISA Adds One Known Exploited Vulnerability to Catalog
Release Date December 11, 2025

CVE-2025-58360 OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability
CISA Adds One Known Exploited Vulnerability to Catalog | CISA
CISA has added one new vulnerability to its KEVCatalog, based on evidence of active exploitation.
www.cisa.gov
December 14, 2025 at 4:48 AM
CISAが2つの既知の脆弱性をカタログに追加

CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Feb 18)

CVE-2021-22175 GitLab サーバーサイドリクエストフォージェリ(SSRF)脆弱性
CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) におけるハードコードされた資格情報の使用に関する脆弱性

www.cisa.gov/news-events/...
CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA
CISA has added two new vulnerabilities to its KEVCatalog, based on evidence of active exploitation.
www.cisa.gov
February 19, 2026 at 12:26 AM
CISA、既知の悪用された脆弱性を1件カタログに追加

CISA Adds One Known Exploited Vulnerability to Catalog #CISA (Dec 11)

CVE-2025-58360 OSGeo GeoServer の XML 外部エンティティ参照の不適切な制限の脆弱性

www.cisa.gov/news-events/...
CISA Adds One Known Exploited Vulnerability to Catalog | CISA
CISA has added one new vulnerability to its KEVCatalog, based on evidence of active exploitation.
www.cisa.gov
December 12, 2025 at 12:21 AM
CISA added another Ivanti flaw to the KEV list because someone bothered to exploit their input validation. It wouldn't be a proper week without another Ivanti patch deadline.

#IvantiAgain #KEVCatalog
May 8, 2026 at 6:51 AM
~Cisa~
CISA added five actively exploited Microsoft vulnerabilities to its KEV catalog, urging remediation.
-
IOCs: CVE-2025-30400, CVE-2025-32701, CVE-2025-32706
-
#CISA #Exploited #KevCatalog #ThreatIntel
CISA Adds Five Known Exploited Vulnerabilities to Catalog
www.cisa.gov
May 13, 2025 at 9:39 PM