Adobe Commerce path traversal Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,
What Happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,
Why This Matters
Publisher reporting describes a security event affecting WSO2. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether WSO2 is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
Sep 25, 2026 10:16
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: ACTIVELY_EXPLOITED
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.
CVE-2026-5430: 2 public repository references found.
Public GitHub reference
CVE-2026-5430 - Draft or TODO
0 stars
Open repositoryPublic GitHub reference
CVE-2026-5430 - WSO2 API Manager - Critical 10.0 - Unauthenticated Account Takeover - WSO2 API Control Plane, WSO2 API Manager, WSO2 Traffic Manager, WSO2 Universal Gateway
0 stars · Python
Open repositoryA public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.
Timeline
-
Incident first seen
Sep 25, 2026 10:16BugSkan first recorded this incident.
-
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
Sep 25, 2026 10:16thehackernews.com · Vulnerability
Sources
thehackernews.com · Sep 25, 2026 10:16
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.