MediumII Cyber Warfare & Critical Infrastructure24 September 2026, Thursday
CISA adds CVSS 10 WSO2 and 9.1 Adobe Commerce flaws to its exploited list; ransomware gangs flagged on TeamCity vulnerability
On 24 September CISA added 2 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue on evidence of active exploitation: CVE-2026-5430, an authentication bypass in WSO2 API products, and CVE-2026-71362, a session takeover flaw in Adobe Commerce/Magento. The same day a TeamCity flaw already in the catalogue was flagged for ransomware use.
According to CISA's alert dated 24 September, federal agencies are subject to directive BOD 26-04, which requires them to prioritise remediation of vulnerabilities in the KEV catalogue. According to SecurityWeek, CVE-2026-5430 has a CVSS score of 10; the patch was released in April 2026, the CVE record was published in early August and the first exploitation was seen on 13 September. The flaw affects API Manager, API Control Plane, Traffic Manager and Universal Gateway; WSO2 has around 1,000 enterprise customers in banking, government, telecoms and logistics. CVE-2026-71362, according to SecurityWeek, scores 9.1; Adobe fixed it in its August 2026 update, and Sansec saw exploitation attempts shortly after the advisory was published on 13 August.
According to BleepingComputer, on 24 September CISA moved the TeamCity flaw CVE-2026-63077, in the catalogue since 5 August, into the list of vulnerabilities used in ransomware campaigns; according to Shadowserver, the number of unpatched internet-facing servers fell from 700 to just over 160 as of 22 September. TeamCity is used by more than 30,000 DevOps teams worldwide, and CISA has flagged 4 TeamCity flaws as exploited since October 2023. In the same period, the Canadian Centre for Cyber Security confirmed exploitation of the Roundcube flaw CVE-2026-48842, patched in May; Shadowserver tracks more than 523,000 internet-exposed Roundcube installations.
Talay assessment
Bottom line
The common pattern is the late exploitation of flaws patched months earlier: around 5 months passed between the patch and the first attack for WSO2, and 4 months for Roundcube. Because API gateways and build servers give access to many systems from a single point, the most likely path is a rise in data breach and ransomware announcements tied to these flaws in the coming weeks.
Likely effects
- Enterprise API securityNegativeWeeks
Because the WSO2 flaw can give access to API back ends and application keys, banking and telecoms face the risk of breaches spreading from a single flaw to many systems.
- E-commerceNegativeWeeks
Because the Adobe Commerce flaw allows customer sessions to be hijacked without authentication, the risk of account and non-card personal data leaks is rising at unpatched stores.
- Turkish institutionsNegativeWeeks
As Magento, Roundcube and WSO2 are also used in e-commerce, hosting and banking infrastructure in Türkiye, institutions that have not reviewed their patch status remain exposed to the same exploitation wave.
Possibilities, ranked
- 1Limited exploitation, patching spreads55%
The KEV additions speed up patching and exploitation remains confined to individual organisational breaches.
Watch: A decline in Shadowserver's counts of unpatched WSO2 and Roundcube systems
- 2Breach announcements multiply35%
Many companies disclose data breaches or ransom demands via the API gateway and e-commerce flaws.
Watch: SEC 8-K cyber incident filings and new victims on ransomware leak sites
- 3Supply chain incident10%
The software supply chain is infiltrated via compromised TeamCity servers, affecting many customers.
Watch: A supply chain warning from CISA or JetBrains
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- WSO2 flaw CVSS▼ 10.0
- Adobe Commerce CVSS▼ 9.1
- Unpatched TeamCity▼ 160+
- Exposed Roundcube▼ 523,000+
Sources
- CISA — CISA Adds Two Known Exploited Vulnerabilities to Catalog
- SecurityWeek — Enterprises Warned of Attacks Exploiting WSO2 Vulnerability
- SecurityWeek — Adobe Commerce Bug Targeted Immediately After Disclosure
- BleepingComputer — CISA: Ransomware gangs now exploiting critical TeamCity flaw
- BleepingComputer — Critical Roundcube flaw now actively exploited in code injection attacks