CISA's list that day

24 September 2026

On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in WSO2 Multiple Products and Adobe Commerce and Magento. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-71362Incorrect AuthorizationAdobe Commerce and MagentoPatch nowForensic triage required by CISA; listed in the last 14 days0.88
CVE-2026-5430Path TraversalWSO2 Multiple ProductsPatch nowForensic triage required by CISA; listed in the last 14 days0.01