CISA adds WSO2 and Adobe Commerce flaws to KEV catalog
CISA added two critical vulnerabilities in WSO2 API Control Plane and Adobe Commerce/Magento to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The flaws are tracked as CVE-2026-5430 and CVE-2026-5431.
- CVE-2026-5430 in WSO2 API Control Plane is a path traversal rated 9.8
- CVE-2026-5431 affects Adobe Commerce and Magento
- CISA confirmed active exploitation of both flaws
- Both vulnerabilities were added to the KEV catalog on Thursday
Read next
Security