WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

A trio of vulnerabilities in popular software solutions has been exploited by attackers, compromising sensitive data and systems. WSO2 and Adobe Commerce flaws have been added to the US Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) list, highlighting the urgency of addressing these issues.

The CISA KEV list is a collection of vulnerabilities that are known to be exploited by attackers in real-world attacks. By adding WSO2 and Adobe Commerce flaws to this list, CISA has effectively raised an alarm for organizations using these software solutions to take immediate action. The affected products include WSO2’s API Manager and Enterprise Integrator, as well as Adobe Commerce, formerly known as Magento.

For those unfamiliar with the technical details, let’s break it down simply: cross-domain privilege escalation is a technique used by attackers to exploit vulnerabilities in software that manage access controls between different domains or systems. When an attacker gains unauthorized access to a system through one domain, they can use this technique to escalate their privileges and spread their attack to other connected systems. Think of it like getting into a house through the front door, only to find out that the back door is also unlocked, allowing you to freely move around the property.

The WSO2 vulnerabilities, in particular, have been linked to several real-world attacks, including a recent incident reported by a major e-commerce company. Attackers exploited these flaws to gain access to sensitive data and disrupt business operations. Adobe Commerce users are also at risk if they haven’t applied security patches or taken other measures to mitigate the vulnerabilities.

What’s particularly concerning about this situation is that these vulnerabilities have been known about for some time, yet many organizations still haven’t taken adequate steps to address them. This highlights a broader issue in the cybersecurity community: the gap between knowledge of vulnerabilities and their effective mitigation. While CISA’s KEV list provides valuable guidance on prioritizing vulnerabilities, it ultimately relies on organizations taking proactive measures to secure their systems.

So what can you do? If your organization uses WSO2 or Adobe Commerce, take immediate action by checking for any outstanding security patches or updates. Consult with your IT team and ensure that all relevant software is up-to-date and configured correctly. This may also be an opportunity to review your overall cybersecurity posture and implement additional controls to prevent similar vulnerabilities from being exploited in the future. Remember, a robust security strategy is not just about patching vulnerabilities; it’s about understanding the risks and taking proactive steps to mitigate them.


Source: The Hacker News — 2026-09-25