CISA Warns of Actively Exploited Flaws in WSO2, Adobe Commerce, SharePoint, and Mikrotik
The Cybersecurity and Infrastructure Security Agency (**CISA**) has issued an urgent warning regarding multiple critical and high-severity vulnerabilities actively exploited in the wild. These include flaws impacting **WSO2** enterprise products, **Adobe Commerce**, **Microsoft SharePoint**, and **Mikrotik RouterOS**, posing significant risks to organizations across various sectors.

**CISA** has added four new vulnerabilities to its Known Exploited Vulnerabilities (**KEV**) catalog, underscoring the immediate threat they pose. Federal agencies are mandated to address these issues promptly, with deadlines approaching rapidly.
### Critical WSO2 Authentication Bypass Under Attack
A critical authentication bypass vulnerability, **CVE-2026-5430**, affecting multiple **WSO2** enterprise products, is being actively exploited. This flaw, with a maximum severity score, impacts **WSO2 API Manager** versions 4.1.0 through 4.6.0, as well as **API Control Plane**, **Traffic Manager**, and **Universal Gateway** versions 4.5.0 and 4.6.0.
The vulnerability stems from the JWT authentication mechanism accepting tokens signed with unsupported algorithms, allowing attackers to compromise administrative accounts and gain full control. Security firm **watchTowr** confirmed observing exploitation attempts, highlighting the broad impact given **WSO2**'s nearly 1,000 customers in banking, government, telecommunications, and logistics.
### Adobe Commerce Flaw Exploited to Hijack Accounts
Another critical-severity flaw, **CVE-2026-71362**, an incorrect authorization vulnerability in **Adobe Commerce** and **Magento** e-commerce platforms, is also being actively leveraged by threat actors. E-commerce security company **Sansec** reported observing its exploitation in the wild, noting that attackers require no existing account, administrator privileges, or user interaction.
### SharePoint and Mikrotik RouterOS Also Targeted
Beyond the critical issues, **CISA** also highlighted two additional vulnerabilities being exploited:
* A high-severity code injection flaw in **Microsoft SharePoint**, tracked as **CVE-2026-65660**.
* A medium-severity pre-authentication SSH state-machine/workflow bypass in **Mikrotik RouterOS**, identified as **CVE-2026-67279**.
### Urgent Action Required
Federal agencies have until Sunday, September 27, to apply recommended updates or mitigations for **WSO2 CVE-2026-5430** and **Adobe Commerce CVE-2026-71362**. For the **Microsoft SharePoint** and **Mikrotik RouterOS** flaws, the deadline is Monday, September 28. **CISA** strongly urges all organizations, not just federal agencies, to prioritize addressing these security issues listed in the **KEV** catalog to protect against active threats.