CISA has added two flaws, one in WSO2’s API Control Plane and one in Adobe Commerce and Magento, to the CISA KEV catalog, the Known Exploited Vulnerabilities list the agency updates only when it has confirmed evidence of active exploitation. The WSO2 flaw, tracked as CVE-2026-5430, is a path traversal bug in the API Control Plane component and carries a CVSS score of 9.8, just short of the maximum on the scale.
What CISA added to the KEV catalog
CISA’s other addition is a vulnerability in Adobe Commerce and Magento, added on the same basis as the WSO2 bug: confirmed exploitation, not theoretical risk. Once a vulnerability lands in the CISA KEV catalog, federal civilian agencies are required under the agency’s binding operational directive to patch or pull the affected software from their networks. Everyone else treats the listing the same way operationally, as confirmation that scanning and exploitation attempts are already under way rather than a future possibility.
That pattern is not new. An unauthenticated RCE in Orkes Conductor got the same treatment earlier this year, added to an active-exploitation list only after attackers were already using it in the wild. The same math applies to WSO2 and Adobe Commerce customers now: assume both are being probed today, not eventually.
Why the WSO2 flaw is described two different ways
The reporting on CVE-2026-5430 does not agree on what the flaw actually is. The Hacker News describes it as a path traversal vulnerability. BleepingComputer calls the same CVE a critical authentication bypass, and its report also folds in a separate SharePoint vulnerability that CISA added to the catalog in the same update.
Path traversal and authentication bypass are not interchangeable descriptions: they point to different attack mechanics and, potentially, different mitigations. Only one can be the accurate technical classification for CVE-2026-5430. NVD’s own entry for the CVE is the primary record, and it is what administrators patching WSO2 deployments should check against, not either outlet’s headline framing.
Anyone running an affected WSO2 API Control Plane instance or an Adobe Commerce or Magento storefront should treat the KEV listing as the operative signal regardless of which description turns out to be precise, and confirm the applied patch or mitigation against the vendor’s own advisory rather than secondary summaries.







