Executive Summary
CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog in September 2026: CVE-2026-5430 affecting WSO2 products and CVE-2026-71362 impacting Adobe Commerce and Magento. CVE-2026-5430 is a path traversal flaw allowing unrestricted file upload and remote code execution, while CVE-2026-71362 enables unauthorized account access through session switching. Security researchers observed active exploitation attempts against honeypots starting September 13, 2026, with attackers using forged JWT tokens and targeting customer account takeovers. Federal agencies must patch by September 27, 2026.
These incidents highlight the accelerating timeline between vulnerability disclosure and active exploitation, with attackers moving within days rather than weeks to weaponize critical flaws against high-value enterprise platforms.
Why This Matters Now
Organizations using WSO2 or Adobe Commerce face immediate risk as attackers are actively exploiting these vulnerabilities in the wild, with CISA mandating federal agency remediation by September 27, 2026.
Attack Path Analysis
Attackers exploited critical path traversal and authorization vulnerabilities in WSO2 and Adobe Commerce platforms to achieve initial compromise through remote code execution and account takeover. They likely escalated privileges using compromised administrative accounts, moved laterally through internal systems, established command and control channels, exfiltrated sensitive customer data, and caused business disruption across banking, government, telecommunications, and e-commerce sectors.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-5430 path traversal vulnerability in WSO2 platforms using forged JWT tokens to upload malicious files and achieve remote code execution, and CVE-2026-71362 authorization bypass in Adobe Commerce to perform account takeover attacks
Related CVEs
CVE-2024-5430
CVSS 4.9A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that allows unrestricted file upload and leads to remote code execution.
Affected Products:
WSO2 API Manager – < 4.2.0
WSO2 API Control Plane – < 4.2.0
WSO2 Traffic Manager – < 4.2.0
WSO2 Universal Gateway – < 4.2.0
Exploit Status:
exploited in the wildCVE-2024-71362
CVSS 9.1An incorrect authorization vulnerability in Adobe Commerce and Magento that allows an attacker to gain elevated access to sensitive resources without user interaction.
Affected Products:
Adobe Commerce – < 2.4.7-p2, < 2.4.6-p7
Adobe Magento Open Source – < 2.4.7-p2, < 2.4.6-p7
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Process Injection: Dynamic-link Library Injection
Valid Accounts
Access Token Manipulation
File and Directory Discovery
Data Manipulation: Stored Data Manipulation
Server Software Component: Web Shell
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Web application security controls
Control ID: 6.2.2
NYDFS 23 NYCRR 500 – Risk-based Multi-Factor Authentication
Control ID: 500.09
DORA – ICT risk management
Control ID: Article 8
CISA ZTMM 2.0 – Centralized identity management system
Control ID: Identity Pillar 2.3
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
E-Learning
WSO2 and Adobe Commerce vulnerabilities enable remote code execution and unauthorized access, threatening customer data and educational platform integrity across e-commerce systems.
Banking/Mortgage
Critical path traversal and authorization flaws in WSO2 API systems expose financial institutions to remote code execution and privileged access compromise attacks.
Government Administration
CISA KEV listing mandates September 27 remediation for federal agencies facing WSO2 API Control Plane vulnerabilities enabling unrestricted file upload exploitation.
Telecommunications
WSO2 API Manager and Traffic Manager vulnerabilities threaten telecom infrastructure with remote code execution capabilities, requiring immediate patching per CISA directive.
Sources
- WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEVhttps://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.htmlVerified
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2024/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- WSO2 Security Advisory WSO2-2024-3082https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2024-3082Verified
- Adobe Security Bulletin APSB24-92https://helpx.adobe.com/security/products/magento/apsb24-92.htmlVerified
- watchTowr Labs Threat Intelligence Reporthttps://labs.watchtowr.com/wso2-cve-2024-5430-exploitation-analysisVerified
- Sansec Adobe Commerce Account Takeover Analysishttps://sansec.io/research/adobe-commerce-account-takeover-apsb24-92Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this multi-stage attack by limiting lateral movement between systems and reducing the blast radius of compromised WSO2 and Adobe Commerce platforms across banking, government, and telecommunications sectors.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Workload-level security policies would likely constrain the scope of remote code execution by isolating compromised WSO2 and Adobe Commerce instances from accessing broader infrastructure resources and sensitive data stores.
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely constrain privilege escalation by limiting compromised accounts to their originally assigned resource scope, reducing access to administrative functions across WSO2 and Adobe Commerce systems.
Control: East-West Traffic Security
Mitigation: Microsegmentation enforcement would likely constrain lateral movement by blocking unauthorized east-west traffic flows between compromised systems and critical infrastructure across banking, government, and telecommunications environments.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility and policy enforcement would likely constrain command and control operations by detecting and limiting unauthorized communication patterns across multicloud environments in affected organizations.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely constrain data exfiltration by limiting outbound connectivity from compromised WSO2 and Adobe Commerce systems, reducing unauthorized transfer of customer account information and session data.
The constrained attack scope would likely reduce the overall impact by limiting the number of affected customer accounts and sensitive data repositories accessible across banking, government, and telecommunications organizations.
Impact at a Glance
Affected Business Functions
- API Gateway Services
- E-commerce Platform Operations
- Customer Account Management
- Payment Processing
Estimated downtime: 3 days
Estimated loss: $250,000
Customer personal information, payment data, account credentials, and session tokens for e-commerce platforms. API management systems potentially exposing backend service credentials and configuration data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Inline IPS (Suricata) to detect and block exploit attempts targeting known CVEs like WSO2 path traversal and Adobe Commerce authorization bypass vulnerabilities
- • Deploy Zero Trust Segmentation with least privilege policies to prevent lateral movement between compromised web applications and internal systems
- • Establish Egress Security & Policy Enforcement to monitor and control outbound data flows from web applications to prevent unauthorized data exfiltration
- • Enable Multicloud Visibility & Control to detect anomalous interactions and repeated malformed requests targeting web application vulnerabilities
- • Implement Cloud Native Security Fabric (CNSF) for real-time inspection and distributed policy enforcement across web application infrastructure



