The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

CISA has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. CVE-2026-5430 affects WSO2 multiple products through a path traversal vulnerability, while CVE-2026-71362 impacts Adobe Commerce and Magento through an incorrect authorization flaw. Both vulnerabilities allow attackers to gain unauthorized access to sensitive systems and data. Under Binding Operational Directive (BOD) 26-04, federal agencies must prioritize rapid remediation of these high-risk vulnerabilities on publicly exposed assets that grant total control post-exploitation.

This development reflects the ongoing escalation in vulnerability exploitation tactics, with threat actors increasingly targeting enterprise software platforms and e-commerce systems. The addition reinforces the critical need for organizations to implement risk-based vulnerability management approaches beyond federal requirements.

Why This Matters Now

These vulnerabilities represent immediate threats to enterprise infrastructure, with active exploitation already confirmed. Organizations using WSO2 or Adobe Commerce platforms face direct risk of unauthorized system access and data compromise until patches are applied.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Both CVE-2026-5430 and CVE-2026-71362 are actively exploited in the wild and can grant attackers total control of affected systems, making them high-priority targets under federal cybersecurity directives.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely have constrained this multi-stage attack by implementing microsegmentation and controlled egress policies. The attack's lateral movement and data exfiltration capabilities would have been significantly reduced through east-west traffic enforcement and identity-aware access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud native security fabric would likely have limited the initial compromise scope by restricting application access to specific network segments and reducing exposed attack surface through workload isolation controls

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely have constrained privilege escalation by restricting service account access to specific resource scopes and limiting cross-service authentication pathways through identity-based access controls

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic security controls would likely have significantly constrained lateral movement by blocking unauthorized inter-workload communications and restricting network reachability between different application tiers and cloud services

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility and control mechanisms would likely have detected and constrained unauthorized command and control establishment by monitoring cross-cloud communications and identifying anomalous remote access tool deployments

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security and policy enforcement would likely have constrained data exfiltration by blocking unauthorized outbound connections and restricting data transfer capabilities to approved external destinations through controlled egress pathways

Impact (Mitigations)

While CNSF segmentation would likely reduce overall business impact scope, compromised workloads within accessible network segments could still experience localized disruption and potential data exposure affecting specific business functions

Impact at a Glance

Affected Business Functions

  • E-commerce Operations
  • Identity and Access Management
  • Customer Data Processing
  • API Gateway Services
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Organizations using vulnerable WSO2 and Adobe Commerce/Magento products face potential exposure of customer personal data, payment information, administrative credentials, and internal system files through path traversal and authorization bypass attacks. Federal agencies are particularly at risk given the active exploitation status.

Recommended Actions

  • • Implement inline IPS with Suricata signatures to detect and block known exploit patterns for CVEs like WSO2 path traversal and Adobe Commerce authorization bypass
  • • Deploy zero trust segmentation with least privilege access controls to prevent lateral movement between cloud workloads and limit blast radius of compromised applications
  • • Enable egress security and policy enforcement to block unauthorized outbound connections and detect data exfiltration attempts through FQDN filtering
  • • Implement encrypted traffic controls for east-west communications to prevent attackers from exploiting unencrypted internal network segments
  • • Deploy multicloud visibility and anomaly detection capabilities to identify suspicious automation, malformed requests, and unauthorized remote access tool deployment

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image