
CISA Adds WSO2 Path Traversal and Adobe Authorization Flaws to KEV After Honeypot Detections
CISA KEV additions for WSO2 and Adobe flaws were driven by independent honeypot evidence predating official listings. Exploitation focused on critical-sector API and commerce platforms with path traversal and authorization weaknesses. Patching deadlines create a narrow window before sustained post-exploitation activity.
CISA's KEV listing mandates FCEB patching by 27 September for both CVEs. CVE-2026-5430 permits unrestricted file upload in WSO2 API Manager and Gateway components through forged JWTs, enabling remote code execution without authentication. CVE-2026-71362 allows attackers to swap customer sessions in Adobe Commerce and Magento, exposing private account data. The additions reflect telemetry from multiple sensors rather than vendor confirmation alone. watchTowr recorded forged JWT exploitation attempts against honeypots starting 13 September and reproduced the WSO2 flaw despite absent public details. Sansec blocked Adobe session-swapping probes in August. Previdian logged a single Australian IP targeting its sensors on 10 September. These independent detections predate the KEV entry by days to weeks, showing attackers prioritized high-value API and e-commerce infrastructure in banking and government sectors before formal disclosure. WSO2 deployments span nearly 1,000 customers in regulated industries where API gateways serve as persistent access points. The pattern matches prior supply-chain targeting of identity and integration platforms, where initial RCE yields long-term persistence rather than immediate data theft. Adobe's lack of updated advisory on exploitation status creates a gap between vendor posture and observed activity. Federal agencies must complete remediation within eight days. Unpatched instances will likely see continued scanning and exploitation attempts, particularly against WSO2 instances lacking JWT validation hardening. Secondary effects include potential lateral movement into connected logistics and telecom networks.
CISA: At least two more WSO2 or Adobe-adjacent CVEs will enter KEV by 15 October 2026 based on continued JWT and session manipulation patterns.
Sources (3)
- [1]CISA Known Exploited Vulnerabilities Catalog(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [2]watchTowr Threat Intelligence Report(https://www.watchtowr.com)
- [3]Sansec Adobe Commerce Advisory(https://sansec.io)