Published: · Region: Global · Category: cyber

Actively Exploited WSO2 and Adobe Commerce Bugs Put Federal Deadline on Patching

Attackers are exploiting vulnerabilities in WSO2 and Adobe Commerce that can allow remote code execution or account session switching. The U.S. Cybersecurity and Infrastructure Security Agency has put both flaws on its Known Exploited Vulnerabilities list and given federal agencies until 27 September to apply fixes.

Two software flaws now being used in real‑world attacks have become urgent patching priorities for security teams running WSO2 products or Adobe Commerce.

In the case of WSO2, a bug in the platform can lead to remote code execution through unrestricted file upload. That means an attacker can upload arbitrary files and get them to run on the server, turning a vulnerable instance into a foothold for deeper compromise.

The Adobe Commerce issue affects the e‑commerce platform’s handling of customer sessions. The flaw can switch a customer session to another account, letting an attacker who has access to one session effectively impersonate another user.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, a list reserved for bugs that are already being used by attackers. Federal civilian agencies have been given until 27 September to patch the flaws.

The combination of active exploitation, remote code execution and account hijacking risk makes these bugs relevant beyond U.S. government networks. Organizations that use WSO2 for identity, access management or APIs, or Adobe Commerce for online retail, face the same technical exposure if they haven’t applied fixes.

Key indicators to watch over the coming days include whether vendors or incident responders report a rise in compromises linked to these specific bugs and whether any organizations publicly disclose breaches tied to WSO2 or Adobe Commerce exploitation. Such disclosures would show how far attackers have already gone beyond probing and into data theft or business disruption.

Sources