Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    September 26, 2026

    ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    September 26, 2026

    Teclara Brings Big-Company Security to the Firms That Can Least Afford a Breach

    September 26, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
    News

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    adminBy adminSeptember 26, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.

    The agency also added CVE-2026-71362, another critical-severity flaw affecting Adobe Commerce, to the list of security issues being leveraged in attacks.

    Hackers are also exploiting two additional vulnerabilities: a high-severity code injection flaw in Microsoft SharePoint tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS identified as CVE-2026-67279.

    For the two critical issues added to the Known Exploited Vulnerabilities (KEV) catalog, federal agencies using the affected products have until  Sunday, September 27, to apply the recommended updates or mitigations, or discontinue their use.

    The CVE-2026-5430 flaw received a maximum severity score and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.

    In the original advisory on May 3, the vendor says that an attacker successfully exploiting the vulnerability could compromise administrative accounts and take full control.

    The problem stems from the JWT authentication mechanism accepting tokens signed with an unsupported algorithm.

    CISA has not shared any details about the attacks, but security firm watchTowr announced on September 15 announced that its honeypots captured exploitation attempts.

    The researchers said they observed a limited number of attempts from one IP address on September 13 using forged JWT tokens against a WSO2 product. However, the attacker targeted the wrong product for CVE-2026-5430.

    watchTowr reproduced the attack on the correct product, where a forged token could expose API endpoints and application credentials.

    Yordan Ganchev, threat intelligence specialist at watchTowr, told BleepingComputer that WSO2 is not a niche target.

    “Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics,” explained Ganchev.

    “Organizations in these sectors can’t afford to wait for exploitation to be formally confirmed.”

    The second critical-severity bug added to the KEV is CVE-2026-71362, an incorrect authorization vulnerability in Adobe’s Commerce and Magento e-commerce platforms.

    Ecommerce security company Sansec observed CVE-2026-71362 being exploited in the wild, saying that threat actors require “no existing account, administrator privileges, or user interaction” to leverage it.

    The deadline for federal agencies to mitigate both vulnerabilities is September 27, but CISA encourages all organizations to take action and prioritize addressing the security issues listed in the KEV.

    For the Microsoft SharePoint and Mikrotik RouterOS flaws, CISA is giving agencies until Monday, September 28 to fix them.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
    admin
    • Website

    Related Posts

    News

    ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    September 26, 2026
    News

    Teclara Brings Big-Company Security to the Firms That Can Least Afford a Breach

    September 26, 2026
    News

    ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

    September 25, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

    September 23, 202649 Views

    How fraudsters target credit unions

    May 4, 202644 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

    September 23, 202649 Views

    How fraudsters target credit unions

    May 4, 202644 Views
    Our Picks

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    September 26, 2026

    ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    September 26, 2026

    Teclara Brings Big-Company Security to the Firms That Can Least Afford a Breach

    September 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.