ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Newsletters › Past editions › ITsecurity Daily — Thursday, 24 September 2026: CISA flags two actively exploited flaws in WSO2 and Adobe Commerce/Magento — patch on the clock

ITSECURITY.GURU

ITsecurity Daily

Daily Briefing

CISA flags two actively exploited flaws in WSO2 and Adobe Commerce/Magento — patch on the clock

Good morning. CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog on 24 September, based on evidence of active exploitation. CISA lists CVE-2026-5430, a path traversal vulnerability in multiple WSO2 products, and CVE-2026-71362, an incorrect authorization vulnerability in Adobe Commerce and Magento. CISA states these types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. If you run either product, match your versions against the vendor advisories and treat remediation as time-sensitive; CISA's alert points to its binding operational directive for prioritizing remediation.

The Register reported that Salesforce Agentforce carried security flaws, dubbed "SalesBleed," that allowed zero-click CRM data theft and anonymous phishing. The Register reported the flaws lead to very unexpected consequences. If you use Agentforce, treat it as affected.

The Hacker News reported that a researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access — the highest level of control over an Android phone — on a OnePlus 15 running the latest OxygenOS, using a malicious app that asks for no special permissions. The Hacker News reports the flaws are unpatched.

Read the full briefing →

Zoom out: Multiple outlets reported the same theme — attackers wiring AI agents into intrusion, from a single operator's automated scans to malware that installs an AI framework on the hosts it hijacks.

Elsewhere

  • SecurityWeek: Roundcube Webmail Vulnerability in Attackers’ Crosshairs Read it
  • The Hacker News: WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV Read it
  • The Hacker News: Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Read it
  • Help Net Security: Stop watching what AI agents say and start watching what they do Read it
  • Help Net Security: Half of threat hunters say bad data is their biggest problem Read it
  • Help Net Security: Your incident count is missing a few incidents Read it
  • Help Net Security: New infosec products of the month: September 2026 Read it
  • The Register: Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs Read it
  • SecurityWeek: Autonomous AI Hacks Raise Thorny Questions of Legal Accountability Read it
  • The Record: Digital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges Read it
  • CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog Read it
  • The Register: Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing Read it

Sources

Every briefing is on the site, with the advisory record behind it. All briefings

You are receiving this because you subscribed at itsecurity.guru.

Headlines from other outlets belong to them; each one credits its outlet and leads to their own report.

All past editions · Get them by email