WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

A Critical Flaw in WSO2 and Adobe Commerce Platforms Exposes Thousands of Users to Cyber Attacks

Thousands of businesses using WSO2 and Adobe Commerce platforms are under threat due to a recently discovered critical flaw that allows hackers to exploit sensitive information. The vulnerability, which has been added to the US Cybersecurity and Infrastructure Security Agency (CISA) catalog of known exploited vulnerabilities (KEV), can be used by attackers to gain unauthorized access to confidential data.

The issue is related to cross-domain privilege escalation, a type of attack where an attacker exploits differences in security settings between different domains or applications to gain elevated privileges. In this case, the flaw allows hackers to map these privileges across different domains, creating a pathway for further exploitation. This can result in unauthorized access to sensitive data, including customer information and financial details.

WSO2 and Adobe Commerce platforms are widely used by e-commerce businesses, with some of the largest companies in the industry relying on them for their online operations. The platforms provide robust security features, but the recent discovery highlights the importance of regular vulnerability assessments and patches. Attackers can use publicly available tools to scan for vulnerable systems, making it essential for administrators to stay up-to-date with the latest security updates.

The CISA KEV catalog is a repository of known exploited vulnerabilities, which are identified by intelligence agencies around the world. The inclusion of this flaw in the catalog serves as an urgent warning to affected businesses to take immediate action and patch their systems before they become targets for cyber attacks. The WSO2 and Adobe Commerce platforms have already issued alerts and provided guidance on remediation steps.

While it is not clear how many businesses have been targeted so far, security experts warn that the vulnerability’s potential impact could be significant given its ease of exploitation. Attackers can use this flaw to gain initial access to a network, from which they can launch further attacks or deploy malware to maintain persistence.

As with any critical security vulnerability, swift action is required to mitigate the risk of attack. Businesses using WSO2 and Adobe Commerce platforms must prioritize patching their systems and conducting thorough vulnerability assessments to identify and address any potential weaknesses. Regular security monitoring and incident response planning are also essential in preventing and responding to cyber attacks.


Source: The Hacker News — 2026-09-25