Cybersecurity agencies have sounded the alarm on a trio of vulnerabilities being exploited by hackers, with serious consequences for organizations that haven’t taken action to patch their systems. The Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are taking advantage of critical flaws in WSO2’s API Manager, Adobe Commerce, and Microsoft SharePoint.
The most pressing issue concerns a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. This bug allows hackers to bypass security checks and gain access to sensitive areas of the system, effectively giving them control over administrative accounts. The problem arises from the way these systems handle JWT tokens; an attacker can create a forged token using an unsupported algorithm that is still accepted by the system.
WSO2’s API Manager, API Control Plane, Traffic Manager, and Universal Gateway versions 4.1.0 through 4.6.0 are all impacted. The vendor has confirmed that exploiting this vulnerability could compromise administrative accounts and grant full control over the system. Security firm watchTowr has observed exploitation attempts using forged JWT tokens against a WSO2 product, reproducing the attack on the correct product to demonstrate its potential impact.
The consequences of not patching these vulnerabilities are severe, especially for organizations in high-risk sectors such as banking, government, and telecommunications. As threat intelligence specialist Yordan Ganchev at watchTowr pointed out, nearly 1,000 customers use WSO2’s technology across these industries, and organizations can’t afford to wait for exploitation to be formally confirmed.
Another critical-severity bug added to the KEV is CVE-2026-71362, an incorrect authorization vulnerability in Adobe Commerce. This flaw allows hackers to gain access without needing existing accounts or administrator privileges, making it a prime target for attackers. Ecommerce security company Sansec has observed this bug being exploited in the wild.
The deadline for federal agencies to mitigate both vulnerabilities is September 27, but CISA encourages all organizations to prioritize addressing these security issues listed in the KEV. Agencies have until Monday, September 28 to fix the Microsoft SharePoint and Mikrotik RouterOS flaws.
Organizations must take immediate action to protect themselves from these vulnerabilities. As the attack on WSO2 demonstrates, even with a relatively small number of exploitation attempts, hackers can still cause significant damage. CISA’s warnings should serve as a wake-up call for organizations to review their security posture and prioritize patching these critical flaws before it’s too late.
Source: Bleeping Computer — 2026-09-25