WSO2, Adobe Commerce, SharePoint, and RouterOS active exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
CISA says attackers are actively exploiting four vulnerabilities across WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS, creating a broad exposure window for internet-facing enterprise systems. The wave includes CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, and CVE-2026-67279, spanning authentication bypass, incorrect authorization, code injection, and pre-auth SSH workflow bypass flaws. CISA placed the two critical issues in the KEV catalog and set mitigation deadlines of September 27 for the critical bugs and September 28 for the SharePoint and RouterOS flaws.
Related Happenings
Cisco security patch release for CVE-2026-20188
Security Patch Release
H score35
First: 06.05.2026 21:06
Last: 06.05.2026 21:06
Sources 1
About this happening:
Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...
Cisco security patch release for CVE-2026-20188
Security Patch ReleaseAbout this happening: Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...
Federal civilian executive branch agency hit by network compromise
Incident
H score21
First: 24.04.2026 23:34
Last: 24.04.2026 23:34
Sources 1
About this happening:
A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...
Federal civilian executive branch agency hit by network compromise
IncidentAbout this happening: A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...
Cisco ASA/FTD code execution and authentication bypass flaws (multiple vulnerabilities)
Vulnerability
H score88
First: 24.04.2026 20:06
Last: 24.04.2026 20:06
Sources 1
About this happening:
Cisco ASA/FTD vulnerabilities CVE-2025-20333 and CVE-2025-20362 are still under active exploitation and can be chained for unauthenticated remote control of af...
Cisco ASA/FTD code execution and authentication bypass flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Cisco ASA/FTD vulnerabilities CVE-2025-20333 and CVE-2025-20362 are still under active exploitation and can be chained for unauthenticated remote control of af...
FIRESTARTER malware on Cisco ASA and FTD devices
Malware Activity
H score33
First: 23.04.2026 15:00
Last: 23.04.2026 15:00
Sources 1
About this happening:
CISA has published analysis of FIRESTARTER, a malware strain that enables remote access and control on Cisco Firepower and Secure Firewall devices, raising the ris...
FIRESTARTER malware on Cisco ASA and FTD devices
Malware ActivityAbout this happening: CISA has published analysis of FIRESTARTER, a malware strain that enables remote access and control on Cisco Firepower and Secure Firewall devices, raising the ris...
Latest development: 24.04.2026 23:34
CISA, NCSC-UK, and Cisco detailed Firestarter persistence on Cisco Firepower and Secure Firewall devices running ASA or FTD software, attributing the backdoor to UAT-4356 and linking the activity to ArcaneDoor. The malware modifies CSP_MOUNT_LIST, stores a copy in /opt/cisco/platform/logs/var/log/svc_samcore.log, restores itself to /usr/bin/lina_cs, and relaunches after termination or reboot; Cisco recommends reimaging and upgrading to fixed releases, or using a cold restart only if reimaging is not possible.
Microsoft April 2026 Patch Tuesday security update (165 CVEs)
Security Patch Release
H score62
First: 15.04.2026 00:22
Last: 15.04.2026 00:22
Sources 1
About this happening:
Microsoft’s April 2026 Patch Tuesday remains a 165-CVE security update that included an actively exploited SharePoint zero-day, a publicly disclosed Defender flaw...
Microsoft April 2026 Patch Tuesday security update (165 CVEs)
Security Patch ReleaseAbout this happening: Microsoft’s April 2026 Patch Tuesday remains a 165-CVE security update that included an actively exploited SharePoint zero-day, a publicly disclosed Defender flaw...
Latest development: 19.08.2026 13:12
CISA warned that hackers are actively exploiting CVE-2026-33824, a critical remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions component that affects supported Windows 10, Windows 11, and Windows Server releases. Microsoft says an unauthenticated attacker can send specially crafted packets over UDP ports 500 or 4500 to execute code on unpatched systems, and CISA added the flaw to its actively exploited catalog while ordering U.S. Federal Civilian Executive Branch agencies to secure devices within three days.
Timeline
-
25.09.2026 20:24 2 articles · 1h ago
CISA adds WSO2 and Adobe Commerce flaws to KEV amid active exploitation
Legal Policy Action UpdateCISA warned that hackers are exploiting CVE-2026-5430 in WSO2 products, CVE-2026-71362 in Adobe Commerce, CVE-2026-65660 in Microsoft SharePoint, and CVE-2026-67279 in Mikrotik RouterOS. The agency placed the two critical issues in the Known Exploited Vulnerabilities catalog and told federal agencies to apply updates or mitigations for those flaws by September 27, while SharePoint and RouterOS remediation is due September 28.
Show sources
- CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks — www.bleepingcomputer.com — 25.09.2026 20:24
- CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks — www.bleepingcomputer.com — 25.09.2026 20:24
-
15.09.2026 03:00 1 articles · 10d ago
Forged JWT attempts target the wrong WSO2 product
Exploitation ObservedwatchTowr said its honeypots captured a limited number of exploitation attempts from one IP address on September 13 using forged JWT tokens against a WSO2 product, and the attacker targeted the wrong product for CVE-2026-5430.
Show sources
- CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks — www.bleepingcomputer.com — 25.09.2026 20:24