Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Advisory

CISA Adds Two Actively Exploited Vulnerabilities (CVE‑2026‑5430, CVE‑2026‑71362) to KEV Catalog

CISA announced that a path‑traversal flaw in WSO2 products and an authorization issue in Adobe Commerce/Magento have been added to the Known Exploited Vulnerabilities catalog, indicating active exploitation. Organizations should prioritize patching to meet risk‑based vulnerability‑management expectations and maintain audit‑ready evidence.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 cisa.gov
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
cisa.gov

CISA Adds Two Actively Exploited Vulnerabilities (CVE‑2026‑5430, CVE‑2026‑71362) to KEV Catalog

What It Is — CISA announced that two CVEs have been added to its Known Exploited Vulnerabilities (KEV) Catalog: a path‑traversal flaw in multiple WSO2 products (CVE‑2026‑5430) and an incorrect‑authorization issue in Adobe Commerce and Magento (CVE‑2026‑71362). Both have confirmed evidence of active exploitation.

Exploitability — The vulnerabilities are listed in the KEV Catalog precisely because threat actors are exploiting them in the wild; no public proof‑of‑concept is required for the advisory.

Affected Products — WSO2 integration and API‑management suites; Adobe Commerce and Magento e‑commerce platforms.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a continuous vulnerability‑management control that can surface newly‑exploited flaws across all public‑facing assets.
  • Provides audit‑ready evidence that an organization is prioritizing remediation of high‑risk findings, a key requirement for defensible compliance reporting.
  • Aligns with the control objective of identifying, assessing, and remediating vulnerabilities—a single control that satisfies multiple frameworks (e.g., NIST CSF 2.0, ISO 27001, SOC 2).

Recommended Actions

  • Inventory all public‑exposed assets running WSO2 or Adobe Commerce/Magento.
  • Verify patch availability; apply the vendor‑provided fixes immediately.
  • Record remediation steps in your control‑evidence repository to demonstrate due diligence.
  • Re‑scan to confirm the vulnerability is no longer present and update your risk register.

Source: CISA Advisory – KEV Catalog Update, 24 Sep 2026

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →