FR
live
tag

#cisa-kev

CISA adds actively exploited WSO2 and Adobe Commerce flaws to its KEV catalog

On September 24, 2026, CISA added the path traversal flaw CVE-2026-5430 in WSO2 and the broken authorization flaw CVE-2026-71362 in Adobe Commerce and Magento to its Known Exploited Vulnerabilities catalog, both of them already exploited in the wild. U.S. federal agencies must patch by September 27, and any organization exposing these products should do the same without waiting.

A CVSS 10 flaw turns Kestra into an unauthenticated root shell

On September 2, 2026, CISA added CVE-2026-49869 to its KEV catalog: a CVSS 10 command injection in the open-source orchestrator Kestra, caused by a path comparison that lets any endpoint ending in ’configs’ through. Move to 1.0.45 or 1.3.21 before the September 5 federal deadline, then check whether the instance was already used as an entry point.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss