CISA Warns of Critical Vulnerabilities in WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS Exploited in Active Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning regarding the active exploitation of critical vulnerabilities across several widely used enterprise software platforms, including WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS. These vulnerabilities, if left unaddressed, pose significant risks to organizational security, potentially leading to unauthorized access, data breaches, and system compromise. The agency’s inclusion of these flaws in its Known Exploited Vulnerabilities (KEV) catalog underscores the urgency for immediate remediation efforts by federal agencies and strongly encourages all organizations to prioritize these patches.

Critical Exploits Targeting Enterprise Software

At the forefront of CISA’s alert is a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from the enterprise software provider WSO2. This flaw, which received a maximum severity score, has been identified as being actively exploited by malicious actors. WSO2 API Manager versions 4.1.0 through 4.6.0, as well as API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0, are confirmed to be impacted. The vulnerability arises from an issue within the JWT (JSON Web Token) authentication mechanism, where it incorrectly accepts tokens signed with unsupported algorithms. This oversight can allow attackers to bypass authentication controls, leading to the compromise of administrative accounts and the potential for complete system takeover.

In addition to the WSO2 vulnerability, CISA has also added CVE-2026-71362, another critical-severity flaw, to its KEV catalog. This vulnerability impacts Adobe Commerce and its Magento e-commerce platforms, which are cornerstones for many online businesses. Described as an incorrect authorization flaw, CVE-2026-71362 is particularly concerning as it requires no existing account, administrator privileges, or user interaction from the victim to be exploited. This low barrier to entry makes it an attractive target for threat actors seeking to hijack customer accounts and potentially disrupt e-commerce operations.

Expanding Scope of Exploited Vulnerabilities

The scope of CISA’s warning extends to two additional vulnerabilities that are also being actively exploited. A high-severity code injection flaw in Microsoft SharePoint, identified as CVE-2026-65660, is a significant concern for organizations relying on this ubiquitous collaboration and document management platform. Code injection vulnerabilities can allow attackers to execute arbitrary code on a server, potentially leading to data theft, system manipulation, or the deployment of further malware.

Furthermore, a medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS, tracked as CVE-2026-67279, has also been flagged. While rated medium, vulnerabilities in network infrastructure devices like routers can have cascading effects, providing attackers with a foothold into an organization’s network and enabling lateral movement.

Timeline and Federal Mandates

CISA’s directives are time-sensitive, particularly for federal agencies. For the two critical-severity flaws added to the KEV catalog—CVE-2026-5430 affecting WSO2 and CVE-2026-71362 affecting Adobe Commerce—federal agencies were mandated to apply the recommended updates or mitigations, or discontinue the use of the affected products by Sunday, September 27. This tight deadline reflects the immediate threat posed by these vulnerabilities.

For the high-severity Microsoft SharePoint vulnerability (CVE-2026-65660) and the medium-severity Mikrotik RouterOS flaw (CVE-2026-67279), federal agencies have been given a slightly extended deadline of Monday, September 28, to implement the necessary fixes. While these deadlines are specific to federal entities, CISA strongly encourages all organizations, regardless of sector, to treat these advisories with the utmost seriousness and to prioritize patching these vulnerabilities to protect their systems and data.

Deep Dive into WSO2 Vulnerability (CVE-2026-5430)

The WSO2 vulnerability, CVE-2026-5430, stands out due to its critical severity and the potential for complete system compromise. The issue lies in the way WSO2’s API Manager handles JWT authentication. JWTs are commonly used for securely transmitting information between parties as a JSON object. They are digitally signed to verify the sender’s identity and ensure the message hasn’t been altered. However, CVE-2026-5430 exploits a weakness where the system accepts tokens that have been signed using algorithms that are not supported or are considered insecure. This allows an attacker to craft a malicious JWT with a forged signature, which the WSO2 product then erroneously trusts.

WSO2’s own security advisory, originally published on May 3, explicitly states that an attacker who successfully exploits this vulnerability can compromise administrative accounts and gain full control over the affected systems. This level of access can be devastating, allowing attackers to steal sensitive data, deploy ransomware, or disrupt critical business operations.

Exploitation Evidence and Impact Analysis

While CISA itself has not divulged specific details about the observed attacks, security firm watchTowr provided crucial insights into the exploitation of the WSO2 vulnerability. On September 15, watchTowr announced that its honeypots had detected exploitation attempts. Researchers observed a limited number of attempts originating from a single IP address on September 13, where attackers used forged JWT tokens against a WSO2 product. Notably, in their initial attempts, the attackers targeted an incorrect product. However, watchTowr was able to reproduce the attack on the correct product, demonstrating its efficacy in exposing API endpoints and application credentials.

Yordan Ganchev, a threat intelligence specialist at watchTowr, emphasized the widespread use of WSO2 technology. "Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics," Ganchev stated. He further underscored the critical need for swift action, adding, "Organizations in these sectors can’t afford to wait for exploitation to be formally confirmed." This sentiment highlights the interconnected risk within critical infrastructure sectors, where a breach in one organization can have ripple effects.

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

Adobe Commerce Vulnerability (CVE-2026-71362) and its Implications

The critical-severity flaw in Adobe Commerce, CVE-2026-71362, is equally concerning for the e-commerce landscape. Sansec, an ecommerce security company, has been observing this vulnerability being exploited in the wild. Their findings reveal the alarming ease with which this flaw can be leveraged. Threat actors do not need any pre-existing account, administrator privileges, or even direct user interaction to exploit CVE-2026-71362. This means that a simple visit to a compromised website or an automated scan could be enough for an attacker to gain unauthorized access.

The implications for online retailers are profound. Account hijacking can lead to fraudulent transactions, theft of customer personally identifiable information (PII), damage to brand reputation, and significant financial losses. The ability to exploit this vulnerability without any prior credentials or user action makes it a prime candidate for automated attacks on a large scale, potentially impacting thousands of businesses and millions of customers.

Broader Implications and Recommendations

The concurrent exploitation of vulnerabilities across such diverse and critical software platforms serves as a stark reminder of the persistent and evolving threat landscape. The fact that these flaws are being actively leveraged indicates that threat actors are actively scanning for and exploiting known weaknesses, often before patches are widely deployed.

The inclusion of these vulnerabilities in CISA’s KEV catalog is a strategic move to prioritize remediation efforts. The KEV catalog serves as a living repository of vulnerabilities that are known to be exploited in the wild, thus posing a significant and immediate risk. By mandating action for federal agencies, CISA aims to protect national security and critical infrastructure from potential attacks.

For organizations beyond the federal sector, CISA’s encouragement to address these issues promptly is a strong recommendation. The principle of "defense in depth" suggests that while critical vulnerabilities require immediate attention, a comprehensive security strategy should include regular vulnerability scanning, diligent patch management, robust access controls, and continuous monitoring for suspicious activity.

Understanding the Technical Nuances

CVE-2026-5430 (WSO2): The core issue is the improper validation of cryptographic algorithms used in JWT signing. Modern security practices advocate for strong, well-defined algorithms like RS256 or ES256. An older or weaker algorithm, or one that is not explicitly allowed, could be used by an attacker to forge a signature that the WSO2 system then incorrectly trusts. This is akin to a lock manufacturer accepting a key made from a softer metal that can be easily manipulated.

CVE-2026-71362 (Adobe Commerce): An "incorrect authorization" vulnerability typically means that the system fails to properly check if a user or process has the necessary permissions to perform a requested action. In an e-commerce context, this could mean a regular customer being able to access administrative functions, or an unauthenticated attacker being able to modify order details or access sensitive customer data. This often stems from flaws in how access control lists (ACLs) or role-based access control (RBAC) mechanisms are implemented.

CVE-2026-65660 (Microsoft SharePoint): Code injection vulnerabilities in platforms like SharePoint are highly dangerous. They can occur when user-supplied input is not properly sanitized before being used in commands or queries. For example, if a web application takes user input and directly concatenates it into a database query, an attacker could insert malicious SQL commands (SQL injection) or operating system commands (command injection) that would then be executed by the server. In SharePoint’s case, this could manifest in various ways, depending on the specific component and function vulnerable to injection.

CVE-2026-67279 (Mikrotik RouterOS): A "pre-authentication SSH state-machine/workflow bypass" suggests that an attacker can exploit a flaw in the initial stages of establishing an SSH connection before full authentication is completed. SSH is a secure protocol for remote login and command execution. If the state machine or workflow that governs the connection setup has a bypass, an attacker might be able to manipulate the connection process to gain unauthorized access or execute commands without proper authentication. This could potentially allow them to gain privileged access to the router’s configuration or network traffic.

The Path Forward

The CISA alerts serve as a critical call to action. Organizations utilizing WSO2, Adobe Commerce, Microsoft SharePoint, or Mikrotik RouterOS should immediately assess their exposure to these vulnerabilities. This involves identifying the specific versions of the software in use and consulting the vendors’ official security advisories for the most up-to-date patching and mitigation guidance.

Beyond immediate patching, a proactive security posture is essential. This includes:

  • Vulnerability Management Programs: Regularly scanning for and prioritizing vulnerabilities across all systems.
  • Threat Intelligence: Staying informed about emerging threats and exploitation trends.
  • Incident Response Planning: Having well-defined plans in place to respond to security incidents.
  • Security Awareness Training: Educating employees about phishing, social engineering, and secure computing practices.
  • Zero Trust Architecture: Implementing a security model that assumes no implicit trust and requires continuous verification of every user and device.

The current wave of exploited vulnerabilities underscores the dynamic nature of cybersecurity. By understanding the risks, acting swiftly on advisories, and fostering a culture of continuous security improvement, organizations can better defend themselves against the ever-present threat of cyberattacks. The deadlines set by CISA are not merely bureaucratic requirements; they represent a crucial window of opportunity to fortify digital defenses against active and sophisticated adversaries.

Related Posts

U.S. Treasury Sanctions Eight Members of Venezuelan Gang Tren de Aragua for Widespread ATM Jackpotting Fraud

The U.S. Treasury Department has imposed sanctions on eight key members of the notorious Venezuelan criminal organization, Tren de Aragua (TdA), for their central roles in orchestrating a sophisticated and…

GitLab Issues Urgent Patch for Critical AI Gateway Vulnerability Enabling Arbitrary Code Execution

GitLab has issued a critical security advisory, urging its customers to immediately apply patches for a severe vulnerability within its AI Gateway service. This flaw, identified as CVE-2026-90970, poses a…

Leave a Reply

Your email address will not be published. Required fields are marked *

You Missed

Patient Privacy Under Scrutiny as Nurse Allegedly Uses ChatGPT for Medical Notes Without Full Consent

Patient Privacy Under Scrutiny as Nurse Allegedly Uses ChatGPT for Medical Notes Without Full Consent

Free Metro Redux Updates Pave the Way for Metro 2039 as Franchise Surpasses 50 Million Sales Milestone

Free Metro Redux Updates Pave the Way for Metro 2039 as Franchise Surpasses 50 Million Sales Milestone

White House Convenes Tech Giants for Landmark AI Safety Pledge, Officially Redefining the Technology as ‘Super Intelligence’

White House Convenes Tech Giants for Landmark AI Safety Pledge, Officially Redefining the Technology as ‘Super Intelligence’

The Dark Side of AI: How a Startup Aims to Prevent Psychological Harm from Conversational Agents

The Dark Side of AI: How a Startup Aims to Prevent Psychological Harm from Conversational Agents

U.S. Treasury Sanctions Eight Members of Venezuelan Gang Tren de Aragua for Widespread ATM Jackpotting Fraud

U.S. Treasury Sanctions Eight Members of Venezuelan Gang Tren de Aragua for Widespread ATM Jackpotting Fraud

How to Adjust the Audio Quality in Apple Music and Maximize Your High-Fidelity Listening Experience

How to Adjust the Audio Quality in Apple Music and Maximize Your High-Fidelity Listening Experience