ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Briefings › CISA flags two actively exploited flaws in WSO2 and Adobe Commerce/Magento — patch on the clock
IT SECURITY DESK

CISA flags two actively exploited flaws in WSO2 and Adobe Commerce/Magento — patch on the clock

A day dominated by active exploitation and AI-driven intrusion, led by two vulnerabilities CISA says attackers are already using.

CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog on 24 September, based on evidence of active exploitation. CISA lists CVE-2026-5430, a path traversal vulnerability in multiple WSO2 products, and CVE-2026-71362, an incorrect authorization vulnerability in Adobe Commerce and Magento. CISA states these types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. If you run either product, match your versions against the vendor advisories and treat remediation as time-sensitive; CISA's alert points to its binding operational directive for prioritizing remediation.

The Register reported that Salesforce Agentforce carried security flaws, dubbed "SalesBleed," that allowed zero-click CRM data theft and anonymous phishing. The Register reported the flaws lead to very unexpected consequences. If you use Agentforce, treat it as affected.

The Hacker News reported that a researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access — the highest level of control over an Android phone — on a OnePlus 15 running the latest OxygenOS, using a malicious app that asks for no special permissions. The Hacker News reports the flaws are unpatched.

On the AI-driven front: BleepingComputer reported that a new botnet malware called Carbonato targets insecure hosts running Docker daemons, installing the Hermes Agent AI framework to take control — lock down exposed Docker daemons. The Register reported that a single crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25-plus other organisations, at an average AI bill of $25 per completed scan. Schneier on Security described a set of malicious npm packages as an impressive piece of malware, adding that its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

Also reported: BleepingComputer reported that a new MacSync variant on macOS now uses public iCloud calendar events to deliver new native payloads, and that private GitLab project email addresses exposed in READMEs and support pages let attackers push code. The Hacker News published its ThreatsDay roundup covering AI search poisoning, an AI coding tool leaking repos, and one-click code execution among 16 stories.

Related