# New WSO2 and Adobe Commerce exploits force U.S. agencies and retailers into race to patch critical flaws

*Friday, September 25, 2026 at 6:20 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-25T06:20:21.855Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18775.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are actively exploiting serious vulnerabilities in WSO2 platforms and Adobe Commerce that can let hackers run code on servers or hijack customer sessions. U.S. cybersecurity authorities have ordered federal agencies to patch by September 27, putting public systems and online retailers on a tight clock to close gaps before more damage is done.

Two widely used software platforms – one powering back‑end services, the other supporting online storefronts – are under active attack from hackers exploiting fresh security flaws, putting both government systems and private‑sector e‑commerce at risk.

Security researchers have confirmed that vulnerabilities in WSO2 products and Adobe Commerce are being weaponized in real‑world attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both bugs to its Known Exploited Vulnerabilities (KEV) catalog and given federal agencies until 27 September to patch their systems, a tight deadline that signals high concern about potential impact.

The WSO2 vulnerability is particularly severe. It allows remote code execution through unrestricted file upload, meaning an attacker who reaches a vulnerable server can upload malicious files and force the system to run them. WSO2 software underpins API gateways, identity and access management, and integration layers for governments, financial firms and large enterprises. A successful exploit doesn’t just compromise one application; it can grant an intruder a foothold in the core plumbing that moves data between critical services.

The Adobe Commerce flaw hits closer to where consumers feel it. Attackers can abuse the bug to switch an active customer session to another account, effectively logging in as a different user without needing that person’s password. For shoppers, that can mean having their accounts accessed without warning. For retailers, it raises the risk that attackers could view order histories, personal details or even payment‑related information, depending on how the site is configured and what other safeguards are in place.

For IT teams in the public sector, CISA’s deadline is more than a calendar note. Agencies must inventory where WSO2 components and Adobe Commerce instances are deployed, test and apply vendor patches, and make sure no exposed systems were already compromised. Many government services rely on WSO2‑style integration layers to connect citizen portals, backend databases and authentication systems. If those layers are breached, attackers can pivot silently for months.

Online merchants and their payment processors face their own scramble. Adobe Commerce, formerly Magento, powers a large number of storefronts, from small niche shops to major brands. Business owners now have to pressure hosting providers and developers to patch quickly, even as the exploit code – or attackers’ understanding of the bug – continues to circulate. A single unpatched instance can become a door into a much wider environment if it’s connected to shared hosting, analytics tools or third‑party plugins.

The strategic concern for governments and regulators is that these two flaws hit very different but equally sensitive layers of the digital economy: the integration middleware that keeps critical infrastructure talking to itself, and the retail platforms that handle everyday consumer transactions. When both tiers are under simultaneous pressure, risk propagates up and down supply chains, from cloud providers and software vendors down to local agencies and shop owners.

This episode also reinforces an uncomfortable reality: patch timelines are being set by attackers, not by IT roadmaps. Once a vulnerability surfaces and attackers start exploiting it, organizations have days – sometimes hours – to move from awareness to action. Federal KEV deadlines like 27 September are an attempt to force hesitant agencies over the line, but private‑sector operators don’t always have the same external push.

A useful way to think about it: you don’t need every site running WSO2 or Adobe Commerce to be hacked for confidence to erode – you only need enough high‑profile breaches for users and partners to question whether their data is safe.

Signals to watch in the coming weeks include any public breach disclosures tied back to these exploits, emergency security updates or configuration changes from WSO2 and Adobe, and whether CISA expands its directives beyond patching to include incident‑response reviews. If major retailers or public services report account takeovers or back‑end compromises linked to these flaws, pressure will rise for broader scrutiny of how quickly critical software vendors and their customers move when the next exploit chain appears.
