Executive Summary
In September 2026, CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The most severe include CVE-2026-5430, a critical authentication bypass in WSO2 API Manager affecting nearly 1,000 customers across banking, government, and telecommunications sectors, and CVE-2026-71362, a critical authorization flaw in Adobe Commerce allowing account hijacking without authentication. Additional vulnerabilities include a code injection flaw in Microsoft SharePoint (CVE-2026-65660) and an SSH bypass in Mikrotik RouterOS (CVE-2026-67279). Federal agencies received 48-72 hour remediation deadlines, with attackers demonstrating sophisticated JWT token forgery techniques and targeting high-value enterprise infrastructure.
This incident highlights the accelerating pace of vulnerability exploitation in 2026, with threat actors increasingly targeting enterprise software platforms that serve as central authentication and API management hubs. The exploitation of WSO2 and Adobe Commerce reflects a strategic shift toward compromising platforms that provide access to multiple downstream systems and customer data.
Why This Matters Now
Enterprise software vulnerabilities are being weaponized within days of disclosure, with attackers specifically targeting authentication and API management platforms that provide privileged access to critical business systems and customer data across multiple industries.
Attack Path Analysis
Attackers exploited critical authentication bypass vulnerabilities in WSO2 (CVE-2026-5430) and Adobe Commerce (CVE-2026-71362) platforms to gain initial access, then leveraged compromised administrative accounts to escalate privileges and move laterally across enterprise environments. The attackers established command and control channels, exfiltrated sensitive data including API credentials and customer information, and potentially disrupted business operations across banking, government, telecommunications, and e-commerce sectors.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-5430 authentication bypass in WSO2 API Manager using forged JWT tokens and CVE-2026-71362 authorization flaw in Adobe Commerce requiring no existing credentials
Related CVEs
CVE-2026-5430
CVSS 10An authentication bypass vulnerability in WSO2 products that allows attackers to compromise administrative accounts through JWT tokens signed with unsupported algorithms.
Affected Products:
WSO2 API Manager – 4.1.0 through 4.6.0
WSO2 API Control Plane – 4.5.0, 4.6.0
WSO2 Traffic Manager – 4.5.0, 4.6.0
WSO2 Universal Gateway – 4.5.0, 4.6.0
Exploit Status:
exploited in the wildCVE-2026-71362
CVSS 9.1An incorrect authorization vulnerability in Adobe Commerce and Magento e-commerce platforms that allows unauthorized access to customer accounts without existing privileges.
Affected Products:
Adobe Commerce – Multiple versions
Adobe Magento – Multiple versions
Exploit Status:
exploited in the wildCVE-2026-65660
CVSS 8.8A code injection vulnerability in Microsoft SharePoint that allows remote code execution through malicious payloads.
Affected Products:
Microsoft SharePoint – Multiple versions
Exploit Status:
exploited in the wildCVE-2026-67279
CVSS 6.5A pre-authentication SSH state-machine bypass vulnerability in Mikrotik RouterOS that allows unauthorized network access.
Affected Products:
MikroTik RouterOS – Multiple versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Modify Authentication Process: Conditional Access Policies
Use Alternate Authentication Material: Application Access Token
Exploitation for Privilege Escalation
Server Software Component: Web Shell
Process Injection
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Notice to Superintendent and Affected Persons
Control ID: 500.08
PCI DSS 4.0 – Security vulnerabilities are identified and managed
Control ID: 6.3.1
DORA – Identification and classification of ICT risk
Control ID: Article 8
CISA ZTMM 2.0 – Multi-factor authentication enforcement
Control ID: Identity.AM-6
NIS2 Directive – Cybersecurity risk management measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Critical WSO2 authentication bypass and Adobe Commerce flaws enable administrative takeover, compromising financial APIs, customer accounts, and payment processing systems requiring immediate patching.
Government Administration
CISA-mandated federal agency compliance deadlines for SharePoint code injection and WSO2 vulnerabilities create urgent remediation requirements to prevent administrative account compromise and data breaches.
Telecommunications
WSO2 API Manager vulnerabilities across telecom infrastructure enable attackers to bypass authentication, compromise service APIs, and gain administrative control over critical communication systems and customer data.
Retail Industry
Adobe Commerce authorization flaws allow unauthorized customer account hijacking without credentials, threatening e-commerce platforms with data theft, payment fraud, and regulatory compliance violations.
Sources
- CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attackshttps://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/Verified
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- WSO2 Security Advisory WSO2-2026-5328https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/Verified
- watchTowr Threat Intelligence Reporthttps://x.com/inkmoro/status/2099925214339727646Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF segmentation would likely constrain attacker reach across WSO2 and Adobe Commerce environments by limiting east-west movement and controlling outbound data paths. The blast radius from authentication bypass vulnerabilities could be significantly reduced through workload isolation and identity-aware routing controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely limit the scope of initial compromise by restricting which systems compromised WSO2 and Adobe Commerce platforms could directly communicate with
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely restrict the scope of administrative privilege abuse by limiting which resources compromised accounts could access across segmented environments
Control: East-West Traffic Security
Mitigation: Micro-segmentation controls would likely constrain lateral movement by blocking unauthorized east-west communication paths between compromised systems and critical backend infrastructure
Control: Multicloud Visibility & Control
Mitigation: Enhanced monitoring and control plane visibility would likely detect and constrain unauthorized command channels by identifying anomalous communication patterns from compromised administrative interfaces
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely constrain data exfiltration by restricting outbound communication paths and monitoring large data transfers from compromised WSO2 and Adobe Commerce systems
While some business disruption may still occur from initially compromised WSO2 and Adobe Commerce platforms, the blast radius would likely be significantly reduced across banking, government, and telecommunications infrastructure
Impact at a Glance
Affected Business Functions
- Enterprise API Management
- E-commerce Transaction Processing
- Document Management and Collaboration
- Network Infrastructure Management
Estimated downtime: 3 days
Estimated loss: $500,000
Administrative credentials, API endpoints, customer account data from e-commerce platforms, corporate documents and communications from SharePoint systems, and network configuration data from compromised router infrastructure
Recommended Actions
Key Takeaways & Next Steps
- • Implement Inline IPS with Suricata signatures to detect and block exploitation attempts against known CVEs like WSO2 and Adobe Commerce vulnerabilities
- • Deploy Zero Trust Segmentation with identity-based policies to prevent lateral movement from compromised administrative accounts across enterprise systems
- • Enable Multicloud Visibility & Control to detect anomalous interactions and repeated malformed requests targeting API endpoints and administrative interfaces
- • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration from compromised WSO2 API credentials and Adobe Commerce customer data
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal administrative behavior and alert on suspicious authentication bypass attempts



