# Critical WSO2 and Adobe Commerce Vulnerabilities Now Under Active Attack

CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog on Thursday, signaling that threat actors actively exploit these flaws in real-world attacks. The inclusion marks a significant escalation for defenders who must now treat these issues as immediate security priorities.

The first vulnerability, CVE-2026-5430, carries a CVSS score of 9.8 and affects WSO2 API Control Plane. This path traversal flaw enables attackers to access files and directories outside their intended scope, potentially exposing sensitive configuration data, API keys, and authentication tokens stored on affected systems. WSO2 API Control Plane manages API governance, security policies, and traffic across microservices architectures. Organizations running this component in production environments face direct risk of credential theft and lateral movement into protected networks.

The second vulnerability impacts Adobe Commerce and its open-source variant Magento. While the specific CVE identifier and technical details remain limited in available disclosures, Adobe Commerce vulnerabilities typically expose e-commerce operations to payment processing compromise, customer data theft, and inventory manipulation. The CVSS score for this flaw was not provided in available information, but inclusion on CISA's KEV list confirms active exploitation.

CISA's KEV catalog serves a critical function in the cybersecurity defense hierarchy. When a vulnerability appears on this list, it means U.S. federal agencies must patch affected systems within specific timeframes mandated by federal binding operational directives. The addition of these two flaws creates compliance obligations for thousands of government agencies and contractors while signaling to the broader security community that these exploits have moved from theoretical to operational.

WSO2 platforms handle API security and identity management for thousands of enterprises globally, from financial institutions to healthcare providers. A path traversal in API Control Plane creates multiple attack vectors. An unauthenticated attacker can retrieve policy files containing API credentials, access logs revealing system behavior, or steal encryption keys used to protect data in transit. Once an attacker gains API credentials, they can impersonate legitimate applications, escalate privileges, or move deeper into interconnected microservices.

Adobe Commerce powers over 300,000 online stores worldwide. Vulnerabilities in this platform directly threaten point-of-sale operations, customer payment data, and backend administrative functions. Even brief exploitation windows allow attackers to install backdoors, exfiltrate customer records, or manipulate pricing and inventory systems.

Organizations using either WSO2 API Control Plane or Adobe Commerce and Magento should prioritize patching immediately. For federal agencies, the timeline is non-negotiable. Enterprise customers should verify patch availability from respective vendors and test fixes in non-production environments before deployment. If patches are unavailable, network segmentation and access controls become interim protective measures. Restrict API Control Plane access to authorized administrative users via VPN or IP allowlisting. Isolate Adobe Commerce instances from untrusted networks where feasible.

Threat actors exploit known vulnerabilities because detection is simple and success rates remain high during the window between public disclosure and widespread patching. CISA's KEV addition confirms this window remains open for both flaws.