CISA Adds Two Exploited Flaws to KEV: WSO2 JWT Bypass (CVE-2026-5430) and Adobe Commerce Account Takeover (CVE-2026-71362)
If your organization runs an internet-facing WSO2 API management platform or an Adobe Commerce / Magento storefront, this is your move-fast-and-fix-it moment. CISA just dropped two actively exploited vulnerabilities into its Known Exploited Vulnerabilities (KEV)…