Executive Summary
CISA has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. CVE-2026-5430 affects WSO2 multiple products through a path traversal vulnerability, while CVE-2026-71362 impacts Adobe Commerce and Magento through an incorrect authorization flaw. Both vulnerabilities allow attackers to gain unauthorized access to sensitive systems and data. Under Binding Operational Directive (BOD) 26-04, federal agencies must prioritize rapid remediation of these high-risk vulnerabilities on publicly exposed assets that grant total control post-exploitation.
This development reflects the ongoing escalation in vulnerability exploitation tactics, with threat actors increasingly targeting enterprise software platforms and e-commerce systems. The addition reinforces the critical need for organizations to implement risk-based vulnerability management approaches beyond federal requirements.
Why This Matters Now
These vulnerabilities represent immediate threats to enterprise infrastructure, with active exploitation already confirmed. Organizations using WSO2 or Adobe Commerce platforms face direct risk of unauthorized system access and data compromise until patches are applied.
Attack Path Analysis
Attackers exploited CVE-2026-5430 (WSO2 path traversal) and CVE-2026-71362 (Adobe Commerce authorization bypass) to gain initial access to cloud environments. They escalated privileges through compromised service accounts, moved laterally across unencrypted network segments, established command and control through unfiltered egress channels, exfiltrated data via unauthorized outbound connections, and caused business disruption through system compromise.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-5430 WSO2 path traversal vulnerability and CVE-2026-71362 Adobe Commerce authorization bypass on publicly exposed cloud applications to gain initial foothold
Related CVEs
CVE-2026-5430
CVSS 10A path traversal vulnerability in WSO2 multiple products allows attackers to access files outside the intended directory structure, potentially leading to unauthorized file access and information disclosure.
Affected Products:
WSO2 Identity Server – < 6.1.0
WSO2 API Manager – < 4.2.0
Exploit Status:
exploited in the wildCVE-2026-71362
CVSS 9.1An incorrect authorization vulnerability in Adobe Commerce and Magento allows attackers to bypass access controls and gain unauthorized access to restricted functionality or data.
Affected Products:
Adobe Commerce – < 2.4.7
Adobe Magento Open Source – < 2.4.7
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Credential Access
Abuse Elevation Control Mechanism: Setuid and Setgid
File and Directory Discovery
OS Credential Dumping: /etc/passwd and /etc/shadow
Valid Accounts: Cloud Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques or Other Methods
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Vulnerability Assessment
Control ID: 500.08
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Application Security
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21(2)(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
WSO2 path traversal and Adobe Commerce authorization vulnerabilities directly impact software development platforms, requiring immediate patching to prevent system compromise and data exfiltration through exploited applications.
E-Learning
WSO2 integration platforms commonly used in educational technology face active exploitation risks, threatening student data through path traversal attacks and unauthorized access to learning management systems.
Retail Industry
Adobe Commerce and Magento authorization flaws expose e-commerce platforms to unauthorized access, compromising customer payment data and violating PCI compliance requirements through lateral movement attacks.
Government Administration
Federal agencies must prioritize KEV catalog vulnerabilities under BOD 26-04, implementing zero trust segmentation and egress controls to prevent privilege escalation in publicly exposed enterprise systems.
Sources
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- WSO2 Security Advisory WSO2-2026-2156https://security.wso2.com/advisories/security-advisory-wso2-2026-2156Verified
- Adobe Security Bulletin APSB26-56https://helpx.adobe.com/security/products/magento/apsb26-56.htmlVerified
- Binding Operational Directive 26-04https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-riskVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained this multi-stage attack by implementing microsegmentation and controlled egress policies. The attack's lateral movement and data exfiltration capabilities would have been significantly reduced through east-west traffic enforcement and identity-aware access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native security fabric would likely have limited the initial compromise scope by restricting application access to specific network segments and reducing exposed attack surface through workload isolation controls
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have constrained privilege escalation by restricting service account access to specific resource scopes and limiting cross-service authentication pathways through identity-based access controls
Control: East-West Traffic Security
Mitigation: East-west traffic security controls would likely have significantly constrained lateral movement by blocking unauthorized inter-workload communications and restricting network reachability between different application tiers and cloud services
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control mechanisms would likely have detected and constrained unauthorized command and control establishment by monitoring cross-cloud communications and identifying anomalous remote access tool deployments
Control: Egress Security & Policy Enforcement
Mitigation: Egress security and policy enforcement would likely have constrained data exfiltration by blocking unauthorized outbound connections and restricting data transfer capabilities to approved external destinations through controlled egress pathways
While CNSF segmentation would likely reduce overall business impact scope, compromised workloads within accessible network segments could still experience localized disruption and potential data exposure affecting specific business functions
Impact at a Glance
Affected Business Functions
- E-commerce Operations
- Identity and Access Management
- Customer Data Processing
- API Gateway Services
Estimated downtime: N/A
Estimated loss: N/A
Organizations using vulnerable WSO2 and Adobe Commerce/Magento products face potential exposure of customer personal data, payment information, administrative credentials, and internal system files through path traversal and authorization bypass attacks. Federal agencies are particularly at risk given the active exploitation status.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline IPS with Suricata signatures to detect and block known exploit patterns for CVEs like WSO2 path traversal and Adobe Commerce authorization bypass
- • Deploy zero trust segmentation with least privilege access controls to prevent lateral movement between cloud workloads and limit blast radius of compromised applications
- • Enable egress security and policy enforcement to block unauthorized outbound connections and detect data exfiltration attempts through FQDN filtering
- • Implement encrypted traffic controls for east-west communications to prevent attackers from exploiting unencrypted internal network segments
- • Deploy multicloud visibility and anomaly detection capabilities to identify suspicious automation, malformed requests, and unauthorized remote access tool deployment



