Find notable cyber news and cases, enriched with sources, timelines, and signals.

WSO2, Adobe Commerce, SharePoint, and RouterOS active exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

CISA says attackers are actively exploiting four vulnerabilities across WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS, creating a broad exposure window for internet-facing enterprise systems. The wave includes CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, and CVE-2026-67279, spanning authentication bypass, incorrect authorization, code injection, and pre-auth SSH workflow bypass flaws. CISA placed the two critical issues in the KEV catalog and set mitigation deadlines of September 27 for the critical bugs and September 28 for the SharePoint and RouterOS flaws.

Related Happenings

Cisco security patch release for CVE-2026-20188

Security Patch Release
H score35 First: 06.05.2026 21:06 Last: 06.05.2026 21:06 Sources 1

About this happening: Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...

Federal civilian executive branch agency hit by network compromise

Incident
H score21 First: 24.04.2026 23:34 Last: 24.04.2026 23:34 Sources 1

About this happening: A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...

Cisco ASA/FTD code execution and authentication bypass flaws (multiple vulnerabilities)

Vulnerability
H score88 First: 24.04.2026 20:06 Last: 24.04.2026 20:06 Sources 1

About this happening: Cisco ASA/FTD vulnerabilities CVE-2025-20333 and CVE-2025-20362 are still under active exploitation and can be chained for unauthenticated remote control of af...

FIRESTARTER malware on Cisco ASA and FTD devices

Malware Activity
H score33 First: 23.04.2026 15:00 Last: 23.04.2026 15:00 Sources 1

About this happening: CISA has published analysis of FIRESTARTER, a malware strain that enables remote access and control on Cisco Firepower and Secure Firewall devices, raising the ris...

Latest development: 24.04.2026 23:34

CISA, NCSC-UK, and Cisco detailed Firestarter persistence on Cisco Firepower and Secure Firewall devices running ASA or FTD software, attributing the backdoor to UAT-4356 and linking the activity to ArcaneDoor. The malware modifies CSP_MOUNT_LIST, stores a copy in /opt/cisco/platform/logs/var/log/svc_samcore.log, restores itself to /usr/bin/lina_cs, and relaunches after termination or reboot; Cisco recommends reimaging and upgrading to fixed releases, or using a cold restart only if reimaging is not possible.

Microsoft April 2026 Patch Tuesday security update (165 CVEs)

Security Patch Release
H score62 First: 15.04.2026 00:22 Last: 15.04.2026 00:22 Sources 1

About this happening: Microsoft’s April 2026 Patch Tuesday remains a 165-CVE security update that included an actively exploited SharePoint zero-day, a publicly disclosed Defender flaw...

Latest development: 19.08.2026 13:12

CISA warned that hackers are actively exploiting CVE-2026-33824, a critical remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions component that affects supported Windows 10, Windows 11, and Windows Server releases. Microsoft says an unauthenticated attacker can send specially crafted packets over UDP ports 500 or 4500 to execute code on unpatched systems, and CISA added the flaw to its actively exploited catalog while ordering U.S. Federal Civilian Executive Branch agencies to secure devices within three days.

Timeline

  1. 25.09.2026 20:24 2 articles · 1h ago

    CISA adds WSO2 and Adobe Commerce flaws to KEV amid active exploitation

    Legal Policy Action Update

    CISA warned that hackers are exploiting CVE-2026-5430 in WSO2 products, CVE-2026-71362 in Adobe Commerce, CVE-2026-65660 in Microsoft SharePoint, and CVE-2026-67279 in Mikrotik RouterOS. The agency placed the two critical issues in the Known Exploited Vulnerabilities catalog and told federal agencies to apply updates or mitigations for those flaws by September 27, while SharePoint and RouterOS remediation is due September 28.

    Show sources
  2. 15.09.2026 03:00 1 articles · 10d ago

    Forged JWT attempts target the wrong WSO2 product

    Exploitation Observed

    watchTowr said its honeypots captured a limited number of exploitation attempts from one IP address on September 13 using forged JWT tokens against a WSO2 product, and the attacker targeted the wrong product for CVE-2026-5430.

    Show sources