Federal cybersecurity authorities have updated the Known Exploited Vulnerabilities catalog to mandate priority remediation for two critical enterprise web application flaws. Threat actors are actively weaponizing path traversal and improper authorization logic to achieve unauthenticated remote code execution and privileged resource access.
The KEV additions cover WSO2 API Control Plane and Traffic Manager vulnerability CVE-2026-5430 alongside Adobe Commerce and Magento authorization bypass vulnerability CVE-2026-71362. Threat monitoring sensors confirm adversaries issuing forged JSON Web Tokens and malformed file upload requests against exposed WSO2 gateways, deploying web shells to execute operating system commands. Under Binding Operational Directive 26-04, federal civilian executive branch agencies face a mandatory October 9 compliance deadline to apply official vendor maintenance releases.
Subverting central API management gateways and e-commerce platforms destroys enterprise data boundaries. Because API Control Planes route internal microservice traffic and hold database connection credentials, an unauthenticated gateway compromise enables threat actors to exfiltrate API secrets and pivot into core enterprise backend subnets.
– Force immediate software maintenance upgrades across all WSO2 API Manager and Traffic Manager installations to current patched builds.
– Apply emergency security updates published by Adobe across all Adobe Commerce and Magento store deployments.
– Restrict public internet visibility of WSO2 management portals using zero trust access proxies and strict IP access control lists.
– Inspect API gateway server directories for unauthorized webshell creations or malformed JWT token assertion attempts.
Enterprise API gateway security demands strict token validation and rapid patch deployment to guarantee core microservice orchestration hubs remain protected from unauthenticated path traversal exploits. #CodeDefence #WSO2 #APIManager #Adobe #Magento #CISA #KEV #RCE #AppSec
/
