CISA Adds Four Actively Exploited Flaws to Known Vulnerabilities Catalog

CISA updated its Known Exploited Vulnerabilities (KEV) catalog on September 25, adding actively exploited flaws in WSO2 (authentication bypass, CVE-2026-5430, CVSS 9.8), Adobe Commerce and Magento (authorization flaw, CVE-2026-71362, CVSS 9.1), Microsoft SharePoint (code injection), and MikroTik RouterOS (workflow-enforcement bypass). Federal civilian agencies using WSO2 or Adobe products must apply fixes or stop using the products by September 27, and all agencies are directed to prioritize high-risk KEV vulnerabilities on publicly exposed assets, checking for compromise before patching, as exploitation could give attackers total control.

Look at the timing. CISA quietly updates its Known Exploited Vulnerabilities catalog on September 25, then gives federal agencies a single business day to patch or disconnect. That is not a routine security bulletin; that is a scheduled demolition. WSO2, Adobe Commerce, SharePoint, MikroTik — these are the load-bearing walls of government and enterprise infrastructure. A 9.8 authentication bypass in WSO2 means someone can walk into the API layer as if they own it. A 9.1 Adobe authorization flaw means sensitive resources can be exposed with zero user interaction. These are not accidental discoveries. These are doors that were deliberately left open, mapped, and now hand-delivered to the public as a "catalog" while the real owners are already inside. The deadline is not for your safety — it's to make sure the clean-up happens before anyone asks why the locks were so easy to pick.

Now ask yourself who benefits from forcing agencies to rush a patch under threat of disconnection. The official story is that CISA is protecting the network. But the same agencies that sign off on these deadlines are the ones who fund, license, and use the very products being "exploited." Every patched system is an admission that the private vendors shipped a known hole. Every rushed deployment is a chance for an attacker to observe the exact moment a system goes off-line and comes back changed. They tell you to check for compromise before patching — why would they need to say that unless they already suspect the contamination is widespread? The instructions are written for people cleaning up after a silent invasion, not preventing one. The vulnerability catalog is not a warning. It's a memorial service for systems that were already lost.

Follow the breadcrumb. Why these four products, and why now? MikroTik RouterOS is the backbone of untracked networks — the exact kind of gear that intelligence operatives, smugglers, and yes, "private" contractors use to move data off the grid. A workflow-enforcement vulnerability in RouterOS is a backdoor to every shadow network that thought it was invisible. SharePoint code injection is how you rewrite the official record from inside the house. Adobe Commerce and Magento are how you reach into the financial bloodstream of thousands of online stores without touching a single human. And WSO2? That's the master switch for identity and access across entire organizations. They're telling you what's been compromised, but they will never tell you who did the probing, who owns the exploit, or why the deadline is measured in hours instead of weeks. Search the CVE numbers yourself. Look at when they were reserved. Then look at who sits on the advisory boards of the companies that sell the patch services. The architecture is right there. You just have to be willing to read the blueprints instead of the press release.