CISA Adds Two Actively Exploited Vulnerabilities (CVE‑2026‑5430, CVE‑2026‑71362) to KEV Catalog
What It Is — CISA announced that two CVEs have been added to its Known Exploited Vulnerabilities (KEV) Catalog: a path‑traversal flaw in multiple WSO2 products (CVE‑2026‑5430) and an incorrect‑authorization issue in Adobe Commerce and Magento (CVE‑2026‑71362). Both have confirmed evidence of active exploitation.
Exploitability — The vulnerabilities are listed in the KEV Catalog precisely because threat actors are exploiting them in the wild; no public proof‑of‑concept is required for the advisory.
Affected Products — WSO2 integration and API‑management suites; Adobe Commerce and Magento e‑commerce platforms.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a continuous vulnerability‑management control that can surface newly‑exploited flaws across all public‑facing assets.
- Provides audit‑ready evidence that an organization is prioritizing remediation of high‑risk findings, a key requirement for defensible compliance reporting.
- Aligns with the control objective of identifying, assessing, and remediating vulnerabilities—a single control that satisfies multiple frameworks (e.g., NIST CSF 2.0, ISO 27001, SOC 2).
Recommended Actions
- Inventory all public‑exposed assets running WSO2 or Adobe Commerce/Magento.
- Verify patch availability; apply the vendor‑provided fixes immediately.
- Record remediation steps in your control‑evidence repository to demonstrate due diligence.
- Re‑scan to confirm the vulnerability is no longer present and update your risk register.