Interestana
Home/News/CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog

CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical security flaws affecting WSO2 and Adobe Commerce, including Magento, to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, March 7, 2024. This inclusion signifies that evidence of active exploitation of these vulnerabilities has been observed. The decision mandates federal agencies to implement specific security measures by March 21, 2024, to mitigate risks associated with these flaws.

The first vulnerability, identified as CVE-2026-5430, is a path traversal vulnerability within the WSO2 API Control Plane. This flaw received a CVSS score of 9.8, indicating a critical severity level. Path traversal vulnerabilities allow attackers to access unauthorized directories and files on a server by manipulating file paths in requests. In the context of an API control plane, such access could lead to the exposure of sensitive configuration data, credentials, or even allow for the execution of arbitrary code.

The second vulnerability, designated as CVE-2023-29078, affects Adobe Commerce and Magento. While the specific type of vulnerability is not detailed in the provided text, its inclusion in the KEV catalog suggests it is being actively exploited in the wild. Adobe Commerce, formerly Magento, is a widely used e-commerce platform, and vulnerabilities within it can have significant implications for businesses operating online, potentially leading to data breaches, financial losses, and reputational damage. The CVSS score for this vulnerability is also critical, though the exact score is not provided.

CISA's KEV catalog is a crucial resource for cybersecurity professionals and organizations, as it highlights vulnerabilities that are actively being targeted by malicious actors. By adding these flaws to the catalog, CISA alerts all federal civilian executive branch (FCEB) agencies to the immediate threat and requires them to apply available security solutions and mitigations. This proactive measure aims to prevent further compromises and protect sensitive government data and systems. The inclusion of these specific vulnerabilities underscores the ongoing threat landscape for web applications and e-commerce platforms, emphasizing the need for continuous monitoring and patching of software.

WSO2 is a technology company that provides a platform for building, integrating, and securing APIs, applications, and digital services. Its API Control Plane is a key component for managing and securing API ecosystems. Adobe Commerce is a comprehensive e-commerce solution used by businesses of all sizes to build and manage online stores. The active exploitation of vulnerabilities in these platforms indicates that attackers are actively seeking to compromise systems that handle sensitive customer data and business operations. The mandated mitigation deadline of March 21, 2024, provides a narrow window for federal agencies to address these critical security gaps.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next