CISA Catalogs Exploited Vulnerabilities Across Major Platforms

CISA Known Exploited Vulnerabilities catalog listing for SharePoint and WSO2

The United States Cybersecurity and Infrastructure Security Agency (CISA) recently expanded the CISA Known Exploited Vulnerabilities catalog, adding four critical flaws currently being weaponized in active, real-world cyberattacks. These devastating threats compromise Microsoft SharePoint servers, WSO2 API management infrastructure, ubiquitous e-commerce platforms like Adobe Commerce and Magento, and ubiquitous network routing devices operating MikroTik RouterOS. Frighteningly, several of these newly cataloged vulnerabilities empower an attacker to execute their malicious payloads completely devoid of pre-existing credentials or any user interaction.

Catastrophic Flaws in WSO2 and Adobe Commerce

The most alarming problem, formally designated CVE-2026-5430, severely afflicts WSO2 API Manager versions 4.1.0 through 4.6.0, alongside API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. WSO2 assigned this vulnerability the absolute maximum CVSS severity score of 10.0 for specific deployment configurations, gravely warning that a successful attack facilitates complete account takeover, explicitly encompassing administrative profiles. You can review the profound implications in the WSO2 security advisory regarding CVE-2026-5430.

This fatal error originates within the validation process for JSON Web Tokens (JWT), the foundational digital passports facilitating secure authorization between interconnected applications and disparate services. The WSO2 architecture erroneously accepted tokens cryptographically signed utilizing an unsupported algorithm; consequently, a sophisticated malicious actor could meticulously forge a counterfeit token and successfully bypass authentication entirely. The vendor released comprehensive patches earlier this spring and adamantly recommends that administrators either install the requisite cumulative update level or urgently migrate to a current, unaffected version.

A second critical vulnerability, CVE-2026-71362, boasting a staggering CVSS score of 9.1, compromises Adobe Commerce, Adobe Commerce B2B, and the foundational Magento Open Source framework. A catastrophic failure in privilege validation allows an attacker to seize unauthorized access to another legitimate customer’s account without requiring any prior authentication. Security researchers at Sansec, who meticulously dissected the official patch, discovered that the underlying system mishandled user identity verification within the active session. This horrific flaw permitted an attacker to arbitrarily switch a session to a different customer, thereby exposing their complete profile and highly sensitive personal data. For a deep technical dive, refer to the Sansec research detailing the Adobe Commerce account takeover vulnerability.

Adobe ostensibly neutralized CVE-2026-71362 via the August APSB26-92 security update. At the precise moment that bulletin was published, the corporation publicly declared possessing zero intelligence indicating active exploitation of the patched vulnerabilities. Nevertheless, Sansec concurrently asserted that its proprietary defensive architecture was already actively repelling attempts to weaponize CVE-2026-71362. The recent, formal inclusion of this vulnerability within the CISA catalog now undeniably confirms that its exploitation has violently escaped the confines of isolated laboratory environments. Review the official Adobe security bulletin APSB26-92 for Magento for deployment instructions.

Exploitation of Microsoft SharePoint and MikroTik RouterOS

Microsoft SharePoint installations are currently sustaining vicious attacks leveraging CVE-2026-65660, a severe vulnerability carrying an 8.8 CVSS rating. This catastrophic error empowers a minimally privileged user to stealthily inject malicious code and subsequently execute it directly upon the host server across the network. Microsoft deployed the necessary patches for this vulnerability in August, explicitly covering SharePoint Server 2016, SharePoint Server 2019, and the modern SharePoint Server Subscription Edition. In stark contrast to the WSO2 and Adobe Commerce debacles, independently exploiting CVE-2026-65660 strictly necessitates the possession of a valid, active user account. Administrators should consult the Microsoft update guide for CVE-2026-65660.

The fourth cataloged vulnerability, designated CVE-2026-67279, resides deeply within the native SSH server embedded within MikroTik RouterOS. By executing a highly specific sequence of actions, an attacker could force RouterOS to precipitously begin processing commands prior to the successful completion of the user verification handshake. Consequently, an unauthenticated, remote client could illicitly forge, manipulate, and extract files residing within the accessible RouterOS storage volume, explicitly encompassing critical configuration files and sensitive diagnostic telemetry. Independent security researchers exhaustively detailed this profound problem following a meticulous analysis of the September firmware updates.

MikroTik decisively neutralized these interconnected errors within RouterOS versions 6.49.21, 7.23.4, 7.24.2, and 7.25 beta 3. The networking company strongly implores administrators to never expose SSH management interfaces directly to untrusted networks. Following the application of the update, administrators must rigorously audit the device for anomalous unknown users, illicit scripts, and unauthorized configuration modifications. Furthermore, RouterOS possesses the capability to proactively flag a device if it detects established forensic signatures indicating a successful compromise. Read the MikroTik security support advisory for September 2026 to ensure full compliance.

Mandatory Remediation Deadlines

CISA has strategically withheld the specific identities of the threat actors weaponizing these four vulnerabilities, alongside the explicit profiles of the targeted victim organizations. United States Federal Civilian Executive Branch agencies are strictly mandated to eradicate CVE-2026-5430 and CVE-2026-71362 by September 27, while CVE-2026-65660 and CVE-2026-67279 demand remediation no later than September 28. For all other global organizations, the formal inclusion of a problem within the CISA catalog serves as a blaring, unequivocal alarm: administrators must deploy the relevant updates immediately, acknowledging the confirmed reality of active exploitation, and meticulously scrutinize all internet-facing systems for lingering forensic evidence of a successful breach.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply