Federal agencies have until Sunday, September 27, to patch or drop two critical software flaws that attackers are already using, the Cybersecurity and Infrastructure Security Agency said. The two issues were added to the Known Exploited Vulnerabilities catalog. Target dates set by CISA give federal agencies a binding deadline, though the agency encourages all organizations to prioritize the same fixes. The affected products are used in banking, government, telecommunications and logistics, sectors where organizations cannot wait for exploitation to be formally confirmed, according to one researcher.
The authentication bypass tracked as CVE-2026-5430 affects WSO2 API Manager versions 4.1.0 through 4.6.0, along with API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. WSO2's May 3 advisory says an attacker who exploits it could take over administrative accounts and seize full control. The problem lies in the JWT authentication mechanism, which accepts tokens signed with an unsupported algorithm. CISA has not released details about the attacks, but watchTowr said its honeypots captured exploitation attempts.
watchTowr said it saw a limited number of attempts from a single IP address on September 13, using forged JWT tokens against a WSO2 product, though the attacker aimed at the wrong product. The firm reproduced the attack against the correct product, where a forged token exposed API endpoints and application credentials.
Yordan Ganchev, a threat intelligence specialist at watchTowr, said WSO2 is not a niche target. He said the company's technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics. He added that organizations in those sectors cannot afford to wait for exploitation to be formally confirmed.
The second critical flaw, CVE-2026-71362, is an incorrect authorization vulnerability in Adobe's Commerce and Magento e-commerce platforms. Ecommerce security company Sansec observed it being exploited in the wild. Sansec said threat actors need no existing account, administrator privileges, or user interaction to leverage it.
CISA is also giving agencies until Monday, September 28, to fix two other exploited flaws. One is a high-severity code injection issue in Microsoft SharePoint tracked as CVE-2026-65660. The other is a medium-severity pre-authentication SSH state-machine and workflow bypass in Mikrotik RouterOS identified as CVE-2026-67279.
More cybersecurity news from TechManNews.







