Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

CISA warns of active attacks exploiting WSO2, Adobe, SharePoint and MikroTik flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) says attackers are exploiting vulnerabilities in products from WSO2, Adobe, Microsoft and MikroTik. The agency added two critical-severity flaws to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-5430, which affects WSO2 products, and CVE-2026-71362, which affects Adobe Commerce and Magento.

CVE-2026-5430 affects WSO2 API Manager versions 4.1.0 through 4.6.0, as well as API Control Plane, Traffic Manager and Universal Gateway versions 4.5.0 and 4.6.0. WSO2 said in a May 3 advisory that successful exploitation could compromise administrative accounts and give an attacker full control. The flaw involves JWT authentication accepting tokens signed with an unsupported algorithm.

CISA has not published details about the attacks. Security firm watchTowr said its honeypots captured a limited number of attempts from one IP address on September 13. Researchers said the attempts used forged JWT tokens but targeted the wrong product. watchTowr reproduced the attack against the correct product and said a forged token could expose API endpoints and application credentials.

Sansec observed CVE-2026-71362 being exploited. The flaw is an authorization issue in Adobe Commerce and Magento. CISA also listed a high-severity code injection flaw in Microsoft SharePoint, CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine/workflow bypass in MikroTik RouterOS, CVE-2026-67279, as exploited.

Federal agencies have until September 27 to address the two critical flaws and until September 28 to address the SharePoint and RouterOS flaws, by applying updates or mitigations or discontinuing use. CISA encourages all organizations to address vulnerabilities listed in the KEV catalog.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.