The Cybersecurity and Infrastructure Security Agency added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on September 24: a path traversal flaw in WSO2’s API Control Plane, API Manager, Traffic Manager and Universal Gateway products, and an incorrect authorization flaw in Adobe Commerce and Magento. CISA’s alert ties both additions to Binding Operational Directive 26-04, which requires federal civilian agencies to prioritize remediation of KEV-listed bugs on internet-exposed systems and to check whether a system was already compromised before the patch went in, not simply to apply the patch and move on.

The WSO2 flaw allows unrestricted file upload that can lead to remote code execution, a serious outcome for products that typically sit at the center of an organization’s API traffic, authenticating and routing requests between internal services and external partners. The Adobe Commerce and Magento flaw lets an attacker gain elevated access to sensitive resources without any user interaction, a dangerous combination for e-commerce platforms handling customer payment and account data. Independent researchers at watchTowr reported seeing exploitation attempts against the WSO2 flaw in their honeypots dating back to September 13, more than a week before CISA’s catalog addition made the activity official.

The original insight here is less about either individual flaw and more about the gap CISA’s own directive is designed to close: by the time a bug reaches the KEV catalog, watchTowr and similar honeypot operators have often already been tracking exploitation for over a week, the same lag this desk documented in its reporting on CISA’s KEV patch-adoption gap. A security team relying on the KEV catalog alone as its earliest warning system is, by definition, reading last week’s news. Teams running WSO2 API Manager or Adobe Commerce should treat both platforms as priority assets for immediate patching and compromise checks, matching the same management-plane logic this desk raised in covering Check Point and F5’s own KEV additions last week: the infrastructure that manages or authorizes access to everything else is worth defending first.

Source: CISA