{"id":2036,"date":"2026-09-28T13:15:49","date_gmt":"2026-09-28T07:45:49","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=2036"},"modified":"2026-09-30T09:25:47","modified_gmt":"2026-09-30T03:55:47","slug":"cisa-kev-wso2-adobe-commerce-exploitation","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/","title":{"rendered":"CISA KEV Alert: WSO2 CVE-2026-5430 and Adobe Commerce CVE-2026-71362"},"content":{"rendered":"<p>Most security teams keep a backlog of &#8220;patch when we get to it&#8221; vulnerabilities. This week, four of them jumped the queue. CISA confirmed active, real-world exploitation of flaws in WSO2&#8217;s API management suite and Adobe Commerce\/Magento, adding both to its Known Exploited Vulnerabilities (KEV) catalog within a day of each other in late September 2026. Around the same time, CISA also flagged ongoing attacks against Microsoft SharePoint and MikroTik RouterOS. The common thread isn&#8217;t a single attacker or campaign, it&#8217;s that all four sit in front of systems enterprises can&#8217;t easily take offline: API gateways, ecommerce backends, collaboration platforms, and network infrastructure.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Who is affected?<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<strong>Who is affected by CISA KEV CVE-2026-5430 and CVE-2026-71362?<\/strong><br \/>\nThese aren&#8217;t attacks tied to one named threat actor, they&#8217;re vulnerabilities CISA confirmed are being actively exploited, regardless of who&#8217;s behind each attempt. WSO2&#8217;s API management and gateway products are used by roughly a thousand organizations worldwide, concentrated in banking, government, telecommunications, and logistics, sectors where APIs sit at the center of daily operations. Adobe Commerce and Magento, meanwhile, power a large share of mid-size and enterprise online stores, handling customer accounts, sessions, and payment workflows. Both platforms are attractive not because they&#8217;re obscure, but because they&#8217;re widely deployed and often internet-facing. A confirmed KEV listing means CISA has evidence real attackers are already probing or exploiting these systems, not just a theoretical risk sitting in a scan report.<br \/>\n    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2>What happened?<\/h2>\n<table>\n<thead>\n<tr>\n<th>Detail<\/th>\n<th>WSO2 (CVE-2026-5430)<\/th>\n<th>Adobe Commerce\/Magento (CVE-2026-71362)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Added to KEV<\/strong><\/td>\n<td>September 24, 2026<\/td>\n<td>September 24, 2026<\/td>\n<\/tr>\n<tr>\n<td><strong>Federal deadline<\/strong><\/td>\n<td>September 27, 2026<\/td>\n<td>September 27, 2026<\/td>\n<\/tr>\n<tr>\n<td><strong>Affected products<\/strong><\/td>\n<td>API Control Plane, API Manager, Traffic Manager, Universal Gateway (API Manager 4.1.0\u20134.6.0; other components 4.5.0\u20134.6.0)<\/td>\n<td>Adobe Commerce and Magento Open Source<\/td>\n<\/tr>\n<tr>\n<td><strong>CVSS severity<\/strong><\/td>\n<td>9.8 (Critical)<\/td>\n<td>9.1 (Critical)<\/td>\n<\/tr>\n<tr>\n<td><strong>How it works<\/strong><\/td>\n<td>Sources disagree here. WSO2&#8217;s own advisory describes a JWT authentication weakness, the system accepts tokens signed with an unsupported algorithm, which can lead to unauthorized access and admin account takeover. CISA&#8217;s KEV entry instead labels it a path-traversal flaw enabling unrestricted file upload and remote code execution. Until vendor and CISA descriptions align, treat both risk paths as real. Administrators should apply the vendor-prescribed fixes without waiting for clarification, restrict administrative access, and review logs for suspicious authentication, file uploads, and signs of code execution.<\/td>\n<td>An incorrect-authorization flaw that lets an attacker switch a customer&#8217;s session to another account. Researchers at Sansec observed this being exploited without an existing account, admin privileges, or user interaction.<\/td>\n<\/tr>\n<tr>\n<td><strong>Access needed<\/strong><\/td>\n<td>Unauthenticated, per most reporting<\/td>\n<td>None \u2014 no account or interaction required<\/td>\n<\/tr>\n<tr>\n<td><strong>What&#8217;s confirmed<\/strong><\/td>\n<td>Active exploitation attempts observed since at least mid-September 2026; CISA has not confirmed ransomware use<\/td>\n<td>Active exploitation observed and blocked by a third-party security vendor<\/td>\n<\/tr>\n<tr>\n<td><strong>What&#8217;s uncertain<\/strong><\/td>\n<td>The exact technical mechanism (JWT bypass vs. path traversal), and how widespread exploitation is<\/td>\n<td>Full scope of affected merchants<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Separately, CISA added two more actively exploited flaws a day later: <strong>CVE-2026-65660<\/strong>, a code-injection vulnerability in on-premises Microsoft SharePoint Server (2016, 2019, and Subscription Edition) that Microsoft initially labeled as lower-severity &#8220;spoofing&#8221; before revising it to reflect remote code execution risk, and <strong>CVE-2026-67279<\/strong>, an SSH-related flaw in MikroTik RouterOS that can let an unauthenticated client open a session and issue commands. Both carry their own federal remediation deadline of September 28, 2026.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/msp-patch-management.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>How Hexnode UEM MSP Simplifies Patch Management Across Client Environments<\/h4><p>MSPs can standardize patch management across clients while keeping each client's controls & requirements separate.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/how-hexnode-uem-msp-simplifies-patch-management-across-client-environments\/\" aria-label=\"How Hexnode UEM MSP Simplifies Patch Management Across Client Environments\"><\/a><\/div><\/div><\/div><\/p>\n<h2>Why this matters<\/h2>\n<p>These four flaws sit in places most security stacks weren&#8217;t built to watch closely: API gateways, ecommerce checkout flows, document collaboration platforms, and network routers. A firewall or antivirus tool doesn&#8217;t tell you whether a WSO2 gateway just accepted a forged token, or whether a Magento session was silently swapped to a different customer. That visibility gap is exactly what attackers rely on \u2014 not sophistication, but the fact that exploitation of an internet-facing system rarely shows up on endpoint dashboards until something downstream breaks. For enterprises, this means the usual patch-later approach for &#8220;critical but not yet exploited&#8221; vulnerabilities no longer applies once CISA confirms real-world attacks. It also means identity, device, and endpoint signals need to talk to each other, because an attacker who gets past a public-facing app eventually has to touch a device, an account, or a session to do anything useful.<\/p>\n<h2>How Hexnode can help<\/h2>\n<h3><a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a>: Keeping endpoint patch status and compliance visible<\/h3>\n<p>When a KEV entry drops with a two- or three-day remediation window, the first blocker is usually not knowing which devices or servers are exposed. Hexnode UEM gives IT teams a centralized view of device compliance and patch status across managed endpoints, so identifying unpatched or misconfigured endpoints doesn&#8217;t depend on manual inventory checks.<\/p>\n<p>It doesn&#8217;t patch WSO2 or Adobe Commerce itself; those require vendor updates. However, Hexnode can deploy underlying operating system updates and supported application patches to managed Windows and macOS devices, including the admin workstations used to access these systems. IT teams can schedule deployments and track patch status, helping keep those endpoints current and compliant.<\/p>\n<h3><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a>: Watching for suspicious behavior after initial access<\/h3>\n<p>If an attacker does get through a public-facing flaw like the WSO2 or SharePoint issues described here, the next step usually involves reaching an endpoint or an identity. Hexnode XDR correlates endpoint and identity signals to help detect unusual behavior, such as an admin account suddenly active from an unexpected device, earlier in the chain. It&#8217;s a detection and response layer, not a guarantee against exploitation of the underlying vulnerability.<\/p>\n<h3><a href=\"https:\/\/www.hexnode.com\/uem\/features\/hexnode-access\/\" rel=\"noopener\">Hexnode Access<\/a> and <a href=\"https:\/\/www.hexnode.com\/idp\/\" rel=\"noopener\">Hexnode IdP<\/a>: Strengthening workstation and application access<\/h3>\n<p>Hexnode Access lets users sign in to macOS and Windows workstations using cloud identity credentials. It connects local workstation login to the organization\u2019s identity provider and helps administrators control device access.<\/p>\n<p>Hexnode IdP manages access to integrated web and SaaS applications through SSO, MFA, and conditional access policies based on user identity, device compliance, and security context. For sensitive administrative consoles integrated with Hexnode IdP, these policies can restrict sign-ins from devices that fail compliance requirements. This adds protection where IdP policies govern access; it does not establish that those policies would block the specific WSO2 or SharePoint exploits.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-IDP_Usecases-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Hexnode-IDP_Usecases\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-IDP_Usecases-1.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-IDP_Usecases-1-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-IDP_Usecases-1-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-IDP_Usecases-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Hexnode-IDP_Usecases\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Feature Resource \n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode IdP use cases\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Check out this document for a quick glance into Hexnode IdP's capabilities.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/infographics\/hexnode-idp-use-cases\/'>\n                            Get the Infographic\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>What security teams should do next<\/h2>\n<p>CISA&#8217;s confirmation that WSO2 and Adobe Commerce flaws are being actively exploited, alongside ongoing attacks on SharePoint and MikroTik RouterOS, is a reminder that KEV listings exist precisely because theoretical risk has become real activity. The practical response is the same regardless of platform: identify every exposed instance, apply vendor patches or mitigations, rotate any credentials or tokens that may have been exposed, and review logs for signs of prior compromise before assuming a patch alone closes the gap. Where identity and endpoint controls are already in place, through tools like Hexnode UEM, XDR, Access, and IdP, teams can add friction against attackers who make it past a patched-but-not-yet-verified system. Start with an accurate inventory of affected systems this week, not next quarter.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f<\/h5><p>See which devices are exposed before attackers do. Try Hexnode free.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today\u202f\u202f<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most security teams keep a backlog of &#8220;patch when we get to it&#8221; vulnerabilities. This&#8230;<\/p>\n","protected":false},"author":8,"featured_media":2068,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[21],"class_list":["post-2036","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-patch-management","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CISA KEV Alert: WSO2 CVE-2026-5430 &amp; Adobe Flaw<\/title>\n<meta name=\"description\" content=\"CISA warns WSO2 and Adobe Commerce flaws are exploited in attacks, making API and ecommerce patching urgent for enterprises.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CISA KEV Alert: WSO2 CVE-2026-5430 &amp; Adobe Flaw\" \/>\n<meta property=\"og:description\" content=\"CISA warns WSO2 and Adobe Commerce flaws are exploited in attacks, making API and ecommerce patching urgent for enterprises.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-28T07:45:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-30T03:55:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"CISA KEV Alert: WSO2 CVE-2026-5430 and Adobe Commerce CVE-2026-71362\",\"datePublished\":\"2026-09-28T07:45:49+00:00\",\"dateModified\":\"2026-09-30T03:55:47+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/\"},\"wordCount\":1165,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CISA-KEV.png?format=webp\",\"articleSection\":[\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/\",\"name\":\"CISA KEV Alert: WSO2 CVE-2026-5430 & Adobe Flaw\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CISA-KEV.png?format=webp\",\"datePublished\":\"2026-09-28T07:45:49+00:00\",\"dateModified\":\"2026-09-30T03:55:47+00:00\",\"description\":\"CISA warns WSO2 and Adobe Commerce flaws are exploited in attacks, making API and ecommerce patching urgent for enterprises.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CISA-KEV.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CISA-KEV.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"CISA KEV\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-wso2-adobe-commerce-exploitation\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CISA KEV Alert: WSO2 CVE-2026-5430 and Adobe Commerce CVE-2026-71362\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"description\":\"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CISA KEV Alert: WSO2 CVE-2026-5430 & Adobe Flaw","description":"CISA warns WSO2 and Adobe Commerce flaws are exploited in attacks, making API and ecommerce patching urgent for enterprises.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/","og_locale":"en_US","og_type":"article","og_title":"CISA KEV Alert: WSO2 CVE-2026-5430 & Adobe Flaw","og_description":"CISA warns WSO2 and Adobe Commerce flaws are exploited in attacks, making API and ecommerce patching urgent for enterprises.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-28T07:45:49+00:00","article_modified_time":"2026-09-30T03:55:47+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV.png?format=webp","type":"image\/png"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"CISA KEV Alert: WSO2 CVE-2026-5430 and Adobe Commerce CVE-2026-71362","datePublished":"2026-09-28T07:45:49+00:00","dateModified":"2026-09-30T03:55:47+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/"},"wordCount":1165,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV.png?format=webp","articleSection":["Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/","url":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/","name":"CISA KEV Alert: WSO2 CVE-2026-5430 & Adobe Flaw","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV.png?format=webp","datePublished":"2026-09-28T07:45:49+00:00","dateModified":"2026-09-30T03:55:47+00:00","description":"CISA warns WSO2 and Adobe Commerce flaws are exploited in attacks, making API and ecommerce patching urgent for enterprises.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV.png?format=webp","width":1340,"height":700,"caption":"CISA KEV"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-wso2-adobe-commerce-exploitation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"CISA KEV Alert: WSO2 CVE-2026-5430 and Adobe Commerce CVE-2026-71362"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"description":"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2036","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=2036"}],"version-history":[{"count":7,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2036\/revisions"}],"predecessor-version":[{"id":2039,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2036\/revisions\/2039"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/2068"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=2036"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=2036"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}