CISA's list that day
24 September 2026
On CISA added 2 vulnerabilities to its list of exploited vulnerabilities, in WSO2 Multiple Products and Adobe Commerce and Magento. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-71362Incorrect Authorization | Adobe Commerce and Magento | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.88 | ||
| CVE-2026-5430Path Traversal | WSO2 Multiple Products | Patch nowForensic triage required by CISA; listed in the last 14 days | 0.01 |