稻草人新闻RSS 聚合阅读

← 返回 🛡️ 网络安全

U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

Security Affairs Pierluigi Paganini 8 小时前 securityaffairs.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products caused by improper verification of JWT signatures, allowing an attacker to use an unsupported signing algorithm to gain unauthorized access and potentially take over accounts.

The second flaw added to the catalog, tracked as CVE-2026-71362 (CVSS score 9.1), is an incorrect authorization vulnerability in Adobe Commerce that can allow an unauthenticated attacker to escalate privileges and gain access to sensitive resources without user interaction. In August 2026, hackers began targeting CVE-2026-71362 shortly after its public disclosure. The vulnerability allows unauthenticated attackers to switch customer sessions, hijack accounts and access private data.

Cybersecurity firm Sansec blocked the first exploitation attempts after Adobe published its advisory. The flaw affects Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches. Adobe released an isolated fix and urged users to patch.

“Adobe has released APSB26-92 as isolated patch files. The update fixes seven vulnerabilities, including an unauthenticated customer account takeover with a CVSS score of 9.1. Sansec Shield already blocks exploitation attempts.” reads the advisory published by Sansec. “Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data.”

Sansec pointed out that an attacker can exploit the flaw without an existing account, administrator privileges, or user interaction.

Adobe fixed how Magento handles customer identity in account sessions. The remaining flaws include stored cross-site scripting and authorization issues.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaws by September 27, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, CISA)

Cyber Crime / September 24, 2026

在原文站打开 ↗

Cloudflare Workers 每 3 分钟抓一批,9 批轮完最快约 27 分钟 · 点右上 ↻ 立刻全量抓一次