Actively Exploited WSO2 and Adobe Commerce Bugs Allow Remote Code Execution and Account Hijacking
Attackers are abusing serious flaws in WSO2 and Adobe Commerce that can enable remote code execution and session switching, prompting U.S. cyber authorities to add both to the Known Exploited Vulnerabilities list and order federal agencies to patch by 27 September.
Two software vulnerabilities in WSO2 and Adobe Commerce are being actively exploited, giving attackers new ways to run their own code on servers and hijack user sessions.
Security reporting says the WSO2 flaw allows remote code execution through an unrestricted file upload mechanism. In practice, that means an attacker who can reach a vulnerable WSO2 instance may be able to upload arbitrary files and then get the system to execute them.
In Adobe Commerce, the highlighted bug lets an attacker switch a customer session to another account. That kind of session switching can expose personal data and potentially give access to information or functions tied to the hijacked account.
The U.S. Cybersecurity and Infrastructure Security Agency has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue, signalling that they’re already being used in real-world attacks. Federal agencies have been given until 27 September to apply patches.
Because WSO2 products often sit in integration backends and Adobe Commerce underpins many online storefronts, unpatched systems could expose sensitive data, enable fraud and open paths deeper into networks.
In the near term, key signals will be whether organisations publicly acknowledge breaches linked to these bugs, how quickly vendors and hosting providers roll out fixes, and whether ransomware groups or more advanced actors begin to adopt these exploits more broadly.
Sources
- OSINT