Follow
Subscribe via Email!

Enter your email address to subscribe to this platform and receive notifications of new posts by email.

CISA Warns of SharePoint, WSO2, and Adobe Commerce Flaws

Federal authorities have added critical vulnerabilities in WSO2 and Adobe Commerce alongside Microsoft SharePoint and Mikrotik flaws to the known exploited list.
Official emblem of the Cybersecurity and Infrastructure Security Agency.

Federal cybersecurity officials issued urgent directives this week after detecting active intrusions against foundational enterprise software across government and corporate networks. Federal agencies face September 27 deadlines. The Cybersecurity and Infrastructure Security Agency warned organizations to immediately remediate a high-severity CISA SharePoint flaw as well as critical bugs in WSO2 integration tools and Adobe Commerce platforms. Threat actors are actively weaponizing unpatched vulnerabilities to breach administrative consoles, bypass perimeter authentication mechanisms, and execute arbitrary server commands [1].

CISA SharePoint Flaw Expands Known Exploited Vulnerabilities

The Cybersecurity and Infrastructure Security Agency added two critical security flaws affecting WSO2 and Adobe Commerce to its Known Exploited Vulnerabilities catalog on Thursday based on direct evidence of active exploitation [2]. The agency confirmed that threat actors are also actively exploiting two additional security issues across enterprise environments: a high-severity code injection vulnerability categorized under the CISA SharePoint flaw advisory and tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine bypass in Mikrotik RouterOS identified as CVE-2026-67279. Remediation expires September 28 [1]. Federal Civilian Executive Branch (FCEB) agencies must patch both critical flaws by September 27, 2026 [2].

Federal authorities regularly mandate rapid remediation whenever internet-exposed enterprise appliances face automated scanning and exploitation by foreign adversaries. These federal patch orders mirror recent defensive interventions where authorities issued a Cisco ISE zero-day emergency patch mandate to halt unauthorized administrative intrusions across government servers. When malicious actors obtain functional exploit code, enterprise platforms experience widespread probing before defensive teams can audit internal server inventories. Addressing the CISA SharePoint flaw and related enterprise perimeter vulnerabilities remains vital to prevent deep network compromise across corporate and public environments [1].

Unpatched enterprise software provides immediate intrusion footholds across corporate networks. The two critical vulnerabilities demand immediate vendor patches [1].

WSO2 API Manager Under Active Attack

While initial warnings emphasized the CISA SharePoint flaw, enterprise software provider WSO2 faces intense security scrutiny after researchers detected active attacks against its integration ecosystem. CVE-2026-5430 carries a 9.8 score. Attackers can achieve unrestricted file upload and remote code execution [2]. The vulnerability impacts WSO2 API Manager versions 4.1.0 through 4.6.0, as well as API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. WSO2 initially disclosed the issue in an advisory on May 3, noting that an adversary successfully exploiting the weakness could compromise administrative accounts to seize complete administrative control over affected host servers [1].

Technical investigations reveal that the vulnerability stems from the JSON Web Token (JWT) authentication mechanism accepting tokens signed with an unsupported algorithm [1]. Attackers exploit this defect through path traversal to bypass gateway validation completely [2]. Although CISA withheld technical operational details, cybersecurity firm watchTowr revealed on September 15 that honeypots recorded live exploitation attempts. Researchers observed probes from a single IP address on September 13 deploying forged JWT tokens against WSO2 infrastructure. The intruder targeted the wrong product during that initial probe [1].

Adobe and CISA security advisory graphic detailing critical vulnerabilities targeted alongside the CISA SharePoint flaw.
Adobe Commerce and Magento e-commerce platforms face active exploitation threats prompting emergency federal remediation orders. (Credit: The Hacker News)

Researchers at watchTowr reproduced the attack against the correct software product, demonstrating that forged tokens expose sensitive API endpoints and application credentials. Principal threat intelligence specialist Yordan Ganchev explained: “Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics.” Ganchev noted that organizations in these sectors cannot delay until exploitation receives formal confirmation [1]. “By the time a vulnerability reaches the KEV catalog, attackers already have days, or, in this instance, weeks, to act,” Ganchev warned [2].

Adobe Commerce and Magento Authorization Flaw

In addition to the CISA SharePoint flaw directives, federal officials targeted an equally severe defect in commercial retail architecture designated as CVE-2026-71362. The bug carries a CVSS score of 9.1 and represents an incorrect authorization vulnerability affecting both Adobe Commerce and Magento e-commerce platforms. Cyber adversaries can exploit this architectural defect to obtain elevated access to sensitive internal resources without requiring administrative privileges or user credentials [2]. Security specialists caution that unauthenticated attackers can interact directly with exposed checkout infrastructure [1].

E-commerce cybersecurity company Sansec observed CVE-2026-71362 undergoing active exploitation in the wild as early as August 2026, detecting and blocking unauthorized exploitation probes aimed at digital storefronts [2]. Sansec researchers noted that threat actors require “no existing account, administrator privileges, or user interaction” to leverage the incorrect authorization vulnerability [1]. The firm explained the underlying operational danger: “The vulnerability lets attackers switch a customer session to another customer account.” That unauthorized manipulation grants intruders immediate access to private customer accounts and sensitive billing data [2].

Independent threat intelligence telemetry gathered by Previdian revealed that a lone IP address originating from Australia attempted to exploit the Adobe Commerce flaw on September 10, 2026, when targeting specialized honeypot sensors. Previdian logged the Australian probe. Can online merchants afford to ignore unconfirmed vendor advisories when honeypots detect live attacks? Adobe has yet to update its security bulletin to confirm exploitation status, leaving defensive teams dependent on third-party security telemetry [2].

Technical Scope of the CISA Warning SharePoint Flaw

Federal attention focused heavily on the CISA SharePoint flaw after security monitors discovered active exploitation involving a high-severity code injection vulnerability tracked as CVE-2026-65660. Microsoft SharePoint operates as a core collaboration and document management backbone for tens of thousands of corporate enterprises and public institutions globally. In corporate intranets, code injection defects allow unauthorized actors to execute arbitrary scripts, compromise document libraries, and harvest employee credentials within authenticated sessions [1]. Attackers frequently pair such injection capabilities with secondary administrative bypasses to pivot across internal enterprise boundaries [2].

Enterprise collaboration software remains a high-value intrusion vector, mirroring previous incidents where automated attacks exploited a critical WordPress flaw for code execution across unpatched web hosting environments. Threat actors consistently target web management frameworks because compromising a single central application server grants visibility over distributed enterprise databases and identity stores. In SharePoint deployments, malicious payload execution undermines document access restrictions and exposes proprietary corporate files to automated data harvesting scripts [1].

The security advisory also incorporated a medium-severity vulnerability impacting Mikrotik RouterOS appliances, cataloged under CVE-2026-67279. RouterOS protects edge boundaries. The flaw involves a pre-authentication SSH state-machine and workflow bypass that undermines device access controls before credential verification occurs. Network routers function as perimeter gateways, making unauthenticated access flaws especially hazardous for enterprise boundaries [1].

Federal Mitigation Deadlines and Defensive Requirements

To counter ongoing attacks, CISA established binding compliance schedules requiring civilian agencies to apply recommended vendor mitigations or discontinue using vulnerable software instances [1]. Federal agencies running affected WSO2 and Adobe Commerce installations must apply emergency updates by Sunday, September 27, 2026, to comply with federal directives [2]. Agencies operating Microsoft SharePoint or Mikrotik RouterOS infrastructure received an extension until Monday, September 28, 2026, to finalize patch deployments. Strict enforcement timelines reflect mounting government concern over automated exploitation chains targeting critical infrastructure [1].

Although federal mandates formally obligate only executive branch civilian agencies, CISA strongly urges commercial businesses and critical infrastructure operators to audit their networks against the Known Exploited Vulnerabilities list immediately. Automated attack scripts do not distinguish between federal servers and private corporate systems when scanning internet-facing address ranges for the CISA SharePoint flaw or exposed WSO2 endpoints [1]. Security teams should verify that perimeter appliances reject unsigned or malformed tokens, restrict administrative interface exposure, and apply vendor security updates promptly to mitigate pre-authentication entry vectors [2].

Honeypots captured live attacks. With commercial honeypots capturing live exploitation attempts across multiple continents, delayed patching leaves enterprise perimeters defenseless against rapid automated intrusion campaigns. Organizations must prioritize remediating the CISA SharePoint flaw and associated perimeter defects before threat actors broaden active intrusion efforts across critical sectors [1].

Sources
  1. ONLINE NEWS Toulas, B. (2026, September 25). CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks. BleepingComputer. [Article Link]
  2. ONLINE NEWS The Hacker News. (2026, September 25). WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV. The Hacker News. [Article Link]

Leave a Comment

Related Posts
Total
0
Share