Cybersecurity agencies are sounding the alarm as hackers continue to exploit a range of critical vulnerabilities affecting popular software products. The latest warning comes from CISA, which has added three new flaws to its list of known exploited vulnerabilities (KEV) and is urging federal agencies to take immediate action.
At the heart of this alert is a critical authentication bypass vulnerability, tracked as CVE-2026-5430, that affects multiple products from enterprise software provider WSO2. This flaw allows an attacker to bypass security checks and gain access to sensitive areas of the system, potentially leading to full control over the affected product. The issue stems from a weakness in the JWT (JSON Web Token) authentication mechanism, which can be exploited by sending forged tokens signed with an unsupported algorithm.
WSO2’s API Manager, API Control Plane, Traffic Manager, and Universal Gateway are all impacted by this flaw, which has been given a maximum severity score. CISA is urging federal agencies using these products to apply the recommended updates or mitigations by September 27, or discontinue their use altogether.
Another critical-severity vulnerability added to the KEV list is CVE-2026-71362, an incorrect authorization issue affecting Adobe Commerce and Magento e-commerce platforms. This flaw can be exploited without requiring any existing account, administrator privileges, or user interaction, making it a particularly worrying threat for online retailers. Sansec has observed exploitation attempts in the wild, highlighting the need for swift action to prevent further attacks.
In addition to these critical issues, CISA is also warning of two other vulnerabilities: a high-severity code injection flaw (CVE-2026-65660) affecting Microsoft SharePoint and a medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS (CVE-2026-67279). Agencies have until September 28 to address these issues.
The fact that hackers are actively exploiting these vulnerabilities is a clear indication of the growing threat landscape. As Yordan Ganchev, threat intelligence specialist at watchTowr, notes, WSO2’s technology is widely used in sectors such as banking, government, and telecommunications, making it a high-priority target for attackers.
Organizations in all sectors are advised to take immediate action to address the security issues listed in the KEV. This includes applying updates, implementing mitigations, or discontinuing use of affected products altogether. By prioritizing security and taking swift action, organizations can minimize the risk of falling victim to these critical vulnerabilities.
In practical terms, this means that IT teams should prioritize patching and updating software as soon as possible, especially if they are using WSO2, Adobe Commerce, Microsoft SharePoint, or Mikrotik RouterOS. It’s also essential for organizations to stay informed about emerging threats and adjust their security posture accordingly. By being proactive and vigilant, we can reduce the risk of cyber attacks and protect our digital assets from harm.
Source: Bleeping Computer — 2026-09-25