Last seen September 25, 2026

Adobe Commerce path traversal Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,

Technical Severity
Low severity
Lifecycle Status

NEW

What Happened

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,

Why This Matters

Publisher reporting describes a security event affecting WSO2. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether WSO2 is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Sep 25, 2026 10:16

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: ACTIVELY_EXPLOITED

Primary entities:

AdobeAmazon AWSWSO2Adobe CommerceMagentoWSO2 API Control Plane

Authoritative Intelligence

CVE CVE-2026-5430 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.

CVE-2026-5430: 2 public repository references found.

HORKimhab/CVE-2026-5430

Public GitHub reference

CVE-2026-5430 - Draft or TODO

0 stars

Open repository
abraxas/CVE-2026-5430

Public GitHub reference

CVE-2026-5430 - WSO2 API Manager - Critical 10.0 - Unauthenticated Account Takeover - WSO2 API Control Plane, WSO2 API Manager, WSO2 Traffic Manager, WSO2 Universal Gateway

0 stars · Python

Open repository

A public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.

Timeline

  • Incident first seen
    Sep 25, 2026 10:16

    BugSkan first recorded this incident.

  • WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
    Sep 25, 2026 10:16

    thehackernews.com · Vulnerability

Sources

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

thehackernews.com · Sep 25, 2026 10:16

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence