# WSO2 and Adobe Commerce Flaws Under Active Attack as CISA Sets Sept. 27 Patch Deadline

*Friday, September 25, 2026 at 6:18 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-25T06:18:10.800Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18773.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are exploiting critical vulnerabilities in WSO2 and Adobe Commerce that can enable remote code execution and account takeover. The U.S. cybersecurity agency has added both issues to its Known Exploited Vulnerabilities list and ordered federal agencies to patch by 27 September.

Two actively exploited software flaws in WSO2 and Adobe Commerce have been added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalogue, triggering a mandatory patch deadline for federal agencies and signalling heightened risk for other organisations.

The WSO2 vulnerability can lead to remote code execution through unrestricted file upload. In practice, that means an attacker who can reach the vulnerable component may be able to upload a malicious file and have it run on the target system, potentially gaining broad control over the affected server.

The Adobe Commerce flaw affects the e‑commerce platform’s handling of customer sessions. It can switch a customer session to another account, creating an opportunity for an attacker to hijack an active session and access data or actions tied to that account.

By placing both issues in the Known Exploited Vulnerabilities catalogue, CISA is indicating that these are not theoretical weaknesses but are already being used in real‑world attacks. U.S. federal agencies have been given until 27 September to apply patches or mitigations.

The order applies directly to U.S. government networks, but the underlying vulnerabilities affect a wider set of users. WSO2 is used in integration and API management, often connecting multiple services, while Adobe Commerce underpins many online storefronts, so a single compromise can have knock‑on effects.

Security teams now have only a short window to identify exposed systems, test vendor fixes where available, and deploy patches without disrupting business operations.

Further updates are likely from vendors and government agencies as they track exploitation. Signals to watch include new technical guidance from WSO2 and Adobe, additional CISA advisories, and reports from security researchers on how attackers are using these bugs and at what scale.
