# New WSO2 and Adobe Commerce Exploits Force U.S. Agencies and Businesses Into Rapid Patch Race

*Friday, September 25, 2026 at 6:16 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-25T06:16:55.454Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18765.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are actively exploiting severe bugs in WSO2 and Adobe Commerce that allow remote code execution and account hijacking, prompting U.S. cybersecurity authorities to order federal agencies to patch by September 27. The flaws put government systems, e‑commerce platforms, and customer data at risk as defenders scramble to close exposed gateways.

Two newly weaponized software vulnerabilities are forcing government agencies and private companies into a fast-moving patch race, after attackers began exploiting critical flaws in WSO2 and Adobe Commerce to seize control of servers and customer accounts. The active attacks have prompted U.S. authorities to put the bugs on a high-priority list and give federal agencies a narrow window to fix them.

Security researchers and officials report that a serious vulnerability in WSO2 products is being used in real-world attacks to achieve remote code execution—that is, to run arbitrary code on a targeted server. The weakness stems from unrestricted file uploads, which allow an attacker to place malicious files on a system and then execute them. Because WSO2 is widely used as integration middleware and API management software, a compromised deployment can serve as a bridge into multiple connected systems.

At the same time, a flaw in Adobe Commerce, Adobe’s widely deployed e‑commerce platform, is also under active exploitation. This vulnerability allows an attacker to switch a customer session to another account. In practice, that can mean hijacking a user’s logged-in session, granting access to personal data, order histories, stored payment methods or administrative functions depending on configuration. For online stores that rely on Adobe Commerce, such an exploit turns a routine shopping session into a potential breach point.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both issues to its Known Exploited Vulnerabilities (KEV) catalog, a curated list of security holes that are confirmed to be used in attacks. Inclusion on that list is not symbolic; it carries operational orders. Federal civilian agencies are required to patch listed vulnerabilities by set deadlines, and in this case have been given until 27 September to remediate the WSO2 and Adobe Commerce bugs or otherwise mitigate the risk.

For government IT teams already juggling large inventories of software and legacy systems, the short timeline means rapid triage. Administrators must locate where WSO2 components and Adobe Commerce platforms are running, test and apply vendor patches or workarounds, and confirm that exposed services are locked down. Failing to move quickly doesn’t just invite theoretical risk—CISA’s decision to list the flaws is grounded in evidence that attackers are already scanning for and hitting unpatched systems.

Private-sector operators, particularly in retail and financial services, face similar pressure without the formal deadlines. An exploited Adobe Commerce instance can expose customer data, trigger regulatory notifications, damage brand trust and potentially incur fines if data protection rules are violated. For companies that use WSO2 to knit together internal and external services, a breach could give attackers a foothold inside the corporate network, from which they can move laterally, deploy ransomware or quietly siphon sensitive information.

Strategically, this episode is another reminder that the attack surface for modern organizations is often defined less by flagship operating systems and more by the specialized platforms that sit between them. Middleware, API gateways and e‑commerce engines are attractive targets because they mediate high-value data and transactions, but sometimes receive less attention than headline software brands when it comes to hardening and monitoring.

The fact that both vulnerabilities are being exploited before some organizations even fully register their existence underscores how compressed the defender’s timeline has become. Attackers track vendor advisories and security research closely, racing to weaponize newly disclosed bugs while defenders are still reading patch notes. The gap between disclosure and exploitation is often measured in days, not weeks.

Organizations watching this play out should focus on concrete signals: vendor patch releases and updated hardening guides, intrusion detection rules tailored to these specific exploits, and any signs of unusual session behavior or file uploads on affected platforms. For policymakers, data on how many federal systems required emergency remediation—and whether any suffered compromise before patches were applied—will shape future debates over baseline security requirements for widely used commercial software.
