Critical Vulnerability

WSO2 and Adobe Commerce bugs exploited, CISA KEV

By Yazoul AI · automated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (K

What Happened

CISA added critical vulnerabilities in WSO2 products and Adobe Commerce/Magento to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation. The inclusion follows reports of attackers targeting unpatched deployments, with one flaw tracked as CVE-2026-5430, a JWT authentication bypass already documented in the wild.

KEV listing requires U.S. federal agencies to remediate within a set deadline, but the designation carries broader weight: it is an authoritative signal that these are not theoretical bugs. Both product lines are widely deployed in enterprise API gateways, identity stacks, and e-commerce storefronts, giving the flaws a large exploitable footprint.

Why It Matters

Adobe Commerce and Magento power thousands of online storefronts processing payments and customer data. WSO2 sits at the heart of API management and identity infrastructure for banks, telecoms, and governments. A successful authentication bypass in either can hand attackers a trusted foothold inside systems that are assumed to be access-controlled.

The KEV addition also means defenders can no longer treat these as “patch when convenient.” Once a CVE reaches KEV, exploit code is either circulating publicly or being actively weaponized, and the window between disclosure and mass scanning collapses to days or hours.

Technical Details

The Adobe Commerce and Magento flaw and the WSO2 issue share a dangerous trait: both can be triggered remotely, often without valid credentials. CVE-2026-5430 concerns a JWT authentication bypass, meaning forged or manipulated tokens can defeat the expected identity check and grant access intended only for authenticated users.

Affected deployments include on-premises and cloud-hosted WSO2 installations and self-hosted or Adobe-hosted Commerce instances. Attackers typically chain such bypasses with post-exploitation steps: enumerating APIs, reading secrets, or injecting skimmer scripts into checkout flows. Because the entry vector is legitimate-looking authentication traffic, detection via signature alone is unreliable.

Immediate Risk

Organizations running unpatched WSO2 or Adobe Commerce/Magento face active exploitation now. E-commerce operators should assume any internet-facing, unpatched storefront is being probed. Financial and telecom operators running WSO2 API gateways should treat this as a credential-integrity incident, not just a patch ticket.

Priority actions:

  • Inventory all WSO2 and Commerce/Magento instances, including dev and staging
  • Apply vendor patches immediately; where patching lags, restrict administrative and management endpoints to trusted networks
  • Rotate JWT signing keys and any secrets exposed on affected systems
  • Review authentication logs for anomalous token use, new admin accounts, or unexpected API calls

Security Insight

A JWT bypass is quietly more dangerous than a typical RCE disclosure, because it does not announce itself with a crash or a payload signature. It looks exactly like normal authenticated traffic, so the compromise is often only visible months later when stolen keys or injected payment scripts surface. Organizations that patched promptly should still audit, because the flaw may have been exploited before the patch existed - the KEV listing confirms abuse occurred during that unpatched window, and rotating trust material is the only way to fully invalidate an attacker’s forged access.

Further Reading

Share:

Never miss a security update

Get real-time security alerts delivered to your preferred platform.

Related News

Related Across Yazoul

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.