SICHERHEIT & DATENSCHUTZ

CISA warns of security vulnerabilities in WSO2 and Adobe Commerce

CISA warns of security vulnerabilities in WSO2 and Adobe Commerce

CISA has identified critical security vulnerabilities in WSO2 and Adobe Commerce that are being actively exploited. Affected users should take immediate action.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two critical security vulnerabilities in the software products WSO2 and Adobe Commerce as well as Magento to its list of known exploited vulnerabilities (KEV). This decision is based on evidence of active exploitation of these vulnerabilities by cybercriminals.

The first vulnerability, classified as CVE-2026-5430, has a CVSS score of 9.8 and affects a Path Traversal vulnerability in the WSO2 API Control Plane. This type of vulnerability allows attackers to access files and directories outside the intended access scope, leading to significant security risks.

The second vulnerability affects Adobe Commerce and Magento, the details of which have also been added to the KEV list. These vulnerabilities can also lead to serious security incidents, as they allow attackers to gain unauthorized access to sensitive data or compromise the integrity of the systems.

CISA has urgently urged the affected companies and organizations to take immediate action to protect their systems. This includes implementing security updates and patches provided by the manufacturers to address the vulnerabilities.

The inclusion in the KEV list means that CISA is aware of active attacks on systems with these vulnerabilities. This is a serious signal for all users of the affected software, as the likelihood of an attack increases in the coming days and weeks.

Response from the Security Community

The security community has already responded to CISA's announcement and warns of the potential consequences of exploiting these vulnerabilities. Experts emphasize that companies using WSO2 or Adobe Commerce should review and adjust their security measures as necessary to protect against possible attacks.

The threat of cyberattacks has increased in recent years, and identifying and reporting such vulnerabilities is crucial for protecting data and systems. CISA plays a central role in monitoring and reporting security risks to help companies and organizations better protect themselves.

The affected companies are urged to review their security policies and ensure that all employees are informed about the risks and the necessary steps for risk mitigation. Training and awareness initiatives can help raise awareness of cyber threats and improve responsiveness in the event of an attack.

CISA has also emphasized that collaboration between government and the private sector is essential to strengthen cyber defense. By sharing information and best practices, companies can better respond to threats and improve their security infrastructure.

comment Kommentare (0)

Noch keine Kommentare. Schreiben Sie den ersten!

Kommentar hinterlassen