CISA also listed three exploited flaws in widely used web platforms. CVE-2026-5430 (CVSS 9.8) is in WSO2 API Manager and related gateway products and can lead to remote code execution. According to watchTowr, attackers were exploiting it against its honeypots from at least September 13, weeks before the KEV listing. WSO2 is used by nearly 1,000 customers across banking, government, telecommunications, and logistics. CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento lets an attacker switch a shopper’s session into another customer’s account. CISA also added CVE-2026-87902, a remote file inclusion flaw in WordPress Core. As watchTowr put it, by the time a flaw reaches the KEV list, attackers may already have had “days, or, in this instance, weeks, to act.”
WHAT TO DO
- Patch WSO2 API gateways and management products now, and review them for unexpected, uploaded files.
- Update Adobe Commerce and Magento storefronts, and watch for customers reporting account or order changes they did not make.
- Update WordPress Core on every site, including marketing and campaign sites run by agencies.
- Keep an inventory of internet-facing web platforms and who owns each one, including sites outside central IT.
- Subscribe to threat-intelligence feeds so you can act on exploitation reports before the KEV listing arrives.
Source: The Hacker News (Ravie Lakshmanan), September 25, 2026; CISA Alert, September 25, 2026