Site icon TheCyberThrone

Four More Vulnerabilities Enter CISA KEV

Advertisements

CISA has added four vulnerabilities affecting WSO2, Adobe Commerce, Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) Catalog.

The common factor is simple: these vulnerabilities are associated with active exploitation.

That immediately changes their priority for vulnerability-management teams. This is no longer just about CVSS scores or theoretical exploitability. Organizations need to identify whether these technologies exist in their environment, whether they are exposed, and whether the required security updates have already been applied.

The Four Vulnerabilities

The latest additions are:

CISA added the four vulnerabilities on September 25, 2026, with different remediation deadlines for U.S. federal agencies.

For other organizations, KEV remains an important threat-intelligence signal because it identifies vulnerabilities that are known to be exploited in real-world attacks.

WSO2 — CVE-2026-5430

CVE-2026-5430 affects multiple WSO2 products, including API Manager, API Control Plane, Traffic Manager and Universal Gateway.

The vulnerability has been described as a critical authentication/security flaw, with exploitation involving weaknesses in the handling of JWT authentication. Public reporting indicates that attackers were observed attempting exploitation against WSO2 environments in September.

The concern here is the position of WSO2 within an enterprise.

API management platforms often sit between external clients and backend applications. A successful compromise could therefore provide an attacker with access to APIs, credentials or application functionality behind the gateway.

For organizations using WSO2, the immediate priority should be identifying affected versions, validating exposure and applying the vendor’s recommended fixes.

Adobe Commerce / Magento — CVE-2026-71362

CVE-2026-71362 is an incorrect authorization vulnerability affecting Adobe Commerce and Magento.

The vulnerability carries a CVSS score of 9.1 and has been associated with exploitation in the wild. Security researchers reported attacks that could allow an attacker to switch customer sessions and gain access to another customer’s account and private information.

For e-commerce environments, this is particularly important because the affected platform can contain customer accounts, transaction information and other sensitive business data.

Organizations running Adobe Commerce or Magento should verify affected versions, confirm that the September security updates have been applied and review relevant application and authentication logs for suspicious activity.

Adobe’s September security bulletin provides the applicable updated versions for Commerce and Magento Open Source.

Microsoft SharePoint — CVE-2026-65660

CVE-2026-65660 affects Microsoft SharePoint and is classified as a code injection vulnerability.

The vulnerability allows an authorized attacker to execute code over a network. Microsoft subsequently reported reliable evidence of observed attacks exploiting the vulnerability, which led to its inclusion in the KEV catalog.

SharePoint is particularly significant in enterprise environments because it is often connected to sensitive documents, business applications and identity infrastructure.

For organizations running on-premises SharePoint, the immediate actions are straightforward:

Identify → Patch → Validate → Investigate.

Identify exposed SharePoint servers and vulnerable versions. Apply Microsoft’s security update. Then review available telemetry for unusual requests, authentication activity, unexpected processes or other signs of compromise.

CISA specifically marked this vulnerability for forensic triage, making post-exploitation investigation an important part of the response.

MikroTik RouterOS — CVE-2026-67279

The fourth addition is CVE-2026-67279, affecting MikroTik RouterOS.

This vulnerability is particularly interesting because its CVSS score is 6.9, significantly lower than the WSO2 and Adobe Commerce vulnerabilities.

Yet it is in KEV because exploitation has been observed.

The vulnerability allows an unauthenticated client to open a session channel and send an execution request. It has also been associated with the MikroTrick exploitation chain involving other RouterOS vulnerabilities.

MikroTik has released fixes across supported RouterOS branches, including 6.49.21, 7.23.4 and 7.24.2. The vendor also recommends ensuring that SSH is not exposed to untrusted networks.

This is an important reminder that network infrastructure cannot be treated as a lower-priority asset simply because a vulnerability carries a moderate CVSS score.

What This KEV Update Tells Us

These four vulnerabilities affect completely different technology layers:

WSO2 — API infrastructure
Adobe Commerce — E-commerce
SharePoint — Enterprise collaboration
MikroTik — Network infrastructure

Different teams may own each of these technologies, but attackers do not care about organizational ownership.

This is where a centralized vulnerability-management process becomes important.

A useful prioritization model should combine:

CVSS + KEV + EPSS + exploit availability + internet exposure + asset criticality + business context

The MikroTik vulnerability is a good example of why CVSS alone is not enough.

A moderate-severity vulnerability on an internet-facing network device with active exploitation can represent a very different operational risk from a critical vulnerability on an isolated internal system.

Exit mobile version