Four more flaws join the exploit catalog

The U.S. Cybersecurity and Infrastructure Security Agency added four vulnerabilities to its Known Exploited Vulnerabilities catalog this week, and all four carry evidence of attacks in the wild rather than a mere proof of concept. Two entries landed on September 24: a critical JWT authentication bypass in WSO2 products tracked as CVE-2026-5430, and an authorization flaw in Adobe Commerce and Magento tracked as CVE-2026-71362. Two more followed on September 25: a code injection flaw in Microsoft SharePoint, CVE-2026-65660, and a pre-authentication SSH bypass in MikroTik RouterOS, CVE-2026-67279.

Under Binding Operational Directive 26-04, federal civilian agencies have hard deadlines: patch or drop the WSO2 and Adobe Commerce issues by September 27, and the SharePoint and MikroTik issues by September 28. The directive also requires agencies to look for signs of compromise before patching, a step plenty of private-sector teams skip. If attackers have had weeks of access, patching without checking first just locks the door behind them.

The WSO2 bypass is the worst of the four

CVE-2026-5430 scores 10.0 on the CVSS scale, dropping to 9.8 in single-tenant deployments. The JWT authentication mechanism accepts tokens signed with algorithms the deployment never configured. An attacker crafts a token with an unsupported algorithm, the server validates it anyway, and the result is unauthorized access up to full administrative account takeover.

The flaw affects WSO2 API Manager 4.1.0 through 4.6.0, plus API Control Plane, Traffic Manager and Universal Gateway versions 4.5.0 and 4.6.0. WSO2 published the advisory, WSO2-2026-5328, on May 3. That is the part worth sitting with: the fix has been available for almost five months, and attackers were still working through the install base in September. WatchTowr’s honeypots caught forged JWT tokens arriving on September 13, tokens already loaded with administrator privileges. The company notes WSO2 technology runs at close to 1,000 customers across banking, government, telecommunications and logistics. Fixes ship through WSO2’s update levels for each product, or as public GitHub patches for older lines.

Adobe Commerce account takeover

CVE-2026-71362 is an incorrect authorization flaw, CWE-863, scoring 9.1. It needs no authentication, no administrator privileges and no user interaction. Exploitation hands the attacker a customer’s session, so they can take over an account that never logged in from anywhere the attacker likes. Adobe shipped the fix in bulletin APSB26-92 on August 11, covering Adobe Commerce 2.4.4 through 2.4.9, Commerce B2B, and Magento Open Source. E-commerce security firm Sansec detected and blocked exploitation attempts in the weeks after disclosure, which is presumably part of what pushed CISA to list it.

Storefronts are a favorite target for a boring reason: they hold payment tokens, addresses and order histories, and they are usually internet-facing by design. An unauthenticated account takeover on a storefront is about as close to a free win as attackers get.

SharePoint code injection

CVE-2026-65660 scores 8.8 and is a code injection flaw, CWE-94, in SharePoint Server 2016, 2019 and Subscription Edition. An authenticated attacker with low privileges can run arbitrary code on the server. Microsoft fixed it in the September 2026 security updates; Subscription Edition builds should be at 16.0.19725.20522 or later. Some coverage has called this a deserialization bug, but Microsoft’s own advisory describes code injection, so patch descriptions should stick to MSRC’s wording.

SharePoint servers tend to sit inside the perimeter with domain credentials nearby, which is why a “high” rated flaw there keeps landing on the KEV list. An authenticated low-privilege foothold on a SharePoint box is a short walk to something worse.

MikroTik and the MikroTrick chain

CVE-2026-67279 is the quiet one, scoring 6.9, and the one most likely to be missed. It is a state machine flaw in RouterOS SSH handling: an unauthenticated client can bypass the rekey requirement, open a session channel, and execute commands that create or modify files. CERT Polska, which published the technical analysis, confirmed exploitation in the wild and showed that chaining it with CVE-2026-86060 yields full administrative access without any credentials. Fixed builds are 6.49.21 and 7.23.4 on the long-term tracks and 7.24.2 on the stable track.

Routers are the devices nobody patches. An edge router with a pre-auth SSH flaw is reachable from the internet on most networks that own one, and the chain ends at full admin.

What administrators should do this week

The patch list is short and concrete:

The pattern behind the list

What stands out here is not any single CVE, it is the timeline. The WSO2 advisory is from May. The Adobe fix shipped in August. Both sat unexploited-in-name-only for months, and both are now confirmed exploited. CISA added them in two batches across two days, which suggests analysts are working through a backlog of real incidents rather than reacting to one event.

For anyone running vulnerability management, the practical takeaway is to stop treating the KEV feed as news and start treating it as input. Feed it into your patch prioritization automatically. By the time a flaw shows up there, attackers have had weeks. Organizations in the sectors WSO2 serves cannot afford to wait for formal confirmation, because the confirmation is the last step, not the first.

Leave a Reply

Your email address will not be published. Required fields are marked *