CyberSecurity News
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
AI summary
The US Cybersecurity and Infrastructure Security Agency has added two critical security flaws to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. One of the vulnerabilities is a path traversal issue in WSO2 API Control Plane, identified as CVE-2026-5430, which has a severity score of 9.8. The other vulnerability affects Adobe Commerce and Magento. These additions indicate that attackers are currently exploiting these flaws. The vulnerabilities have been listed in the KEV catalog, which tracks known exploited vulnerabilities. The listing is based on evidence that these flaws are being actively exploited by attackers.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

