PT-2026-98420 · Undefined · Undefined

CVE-2026-5431

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
CISA added two critical flaws to the KEV catalog yesterday, confirming active exploitation in the wild. Both are being actively targeted.
Technical Breakdown: - CVE-2026-5430 (CVSS 9.8): Path traversal in WSO2 API Control Plane. Allows unauthenticated remote attackers to read arbitrary files or execute code. Likely chained for initial access. - CVE-2026-5431 (CVSS 9.8): Remote code execution in Adobe Commerce and Magento. No further technical detail released yet, but expect it to be wormable given the CVSS score. - MITRE Mapping: Expect T1190 (Exploit Public-Facing Application) for both. WSO2 specifically is a common target for initial access into enterprise API gateways. - IOCs: None published by CISA at this time. Monitor for anomalous outbound connections from WSO2 and Adobe Commerce servers.
Defense: Patch immediately. WSO2 users should check for unauthorized file modifications in the deployment directory. Adobe Commerce/Magento users should verify no webshells dropped in /app/etc/ or /pub/media/ . If you can't patch, isolate these services behind a WAF with strict allowlisting.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-5431

Affected Products

Undefined