CISA added vulnerabilities affecting WSO2 and Adobe Commerce/Magento to its Known Exploited Vulnerabilities catalog after evidence of exploitation, according to reporting published September 26. The additions put two widely used enterprise platforms into the immediate patch-and-hunt queue.

Operators should identify affected deployments, apply the vendors’ supported fixes and mitigations, and review logs for unexpected administrative actions, web-shell indicators, or changes to storefront and identity components. Internet-facing systems should be handled first, with owners documenting whether the fixes completed successfully.

Source: The Hacker News

By Allan