SharePoint, Adobe Commerce and WSO2 flaws now exploited, CISA says
CISA added four actively exploited bugs to its KEV catalog in two days, including a SharePoint flaw Microsoft first rated as a moderate spoofing issue.
By Tech CEO Daily Staff, Newsroom
· 2 min read

The news
CISA added CVE-2026-65660, a code injection flaw in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog on September 25, alongside a MikroTik RouterOS issue (CVE-2026-67279). A day earlier it listed CVE-2026-5430, affecting several WSO2 API products, and CVE-2026-71362, an incorrect-authorization flaw in Adobe Commerce and Magento. Federal agencies were given until September 27 and 28 to remediate.
The SharePoint bug was fixed in Microsoft’s August 11 updates for SharePoint Server 2016, 2019 and Subscription Edition. Microsoft originally described it as a spoofing issue with a CVSS score of 6.5, but The Hacker News reported that the National Vulnerability Database scores it 8.8 and that Microsoft’s CVE record now calls it remote code execution. It requires a low-privileged authenticated user, but researchers say it can be chained with an older, already-patched authentication bypass on sites that allow anonymous access. SecurityWeek reported that exploitation followed public technical write-ups by Viettel Security, and that Microsoft said it had reliable evidence of attacks as of September 25.
For Adobe Commerce, The Hacker News reported a CVSS score of 9.1 and said e-commerce security firm Sansec had blocked exploitation attempts in August; the flaw can let attackers switch a shopper’s session to another customer’s account. For WSO2, the outlet reported a 9.8 score and said watchTowr observed in-the-wild attempts, including forged JWT tokens, since September 13. Affected WSO2 products include API Manager 4.1.0 through 4.6.0.
The numbers
- SharePoint CVSS (NVD)
- 8.8
- Adobe Commerce CVSS
- 9.1
- WSO2 CVSS
- 9.8
- SharePoint patch released
- Aug 11, 2026
Why CEOs should care
These are mainstream business platforms: document collaboration, online storefronts and API gateways. Ask IT to confirm that on-premises SharePoint servers carry the August updates (and the earlier June fix that blocks the anonymous-access chain), that any Adobe Commerce or Magento stores — including those run by agencies — are on the latest release, and that WSO2 gateways are patched.
The SharePoint case is a lesson in triage. A vulnerability labelled “moderate spoofing” turned out to allow code execution, so teams that prioritised strictly by vendor severity may have deferred it. Ask how your patch process handles rating changes and public exploit releases.
What's next
With exploit details public, expect wider scanning. SharePoint 2013, which one researcher says is also affected, is out of support and will not be fixed.
Sources
- GovernmentCISA Adds Two Known Exploited Vulnerabilities to Catalog (Sept 25)— CISA
- GovernmentCISA Adds Two Known Exploited Vulnerabilities to Catalog (Sept 24)— CISA
- ReportMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks— SecurityWeek
- ReportSharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE— The Hacker News
- ReportWSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV— The Hacker News
- ReportCISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks— BleepingComputer
Newsroom
Reporting and analysis from the Tech CEO Daily newsroom. Each story is researched from primary sources — company announcements, regulatory filings and official advisories — and fact-checked before publication.
Spotted an error? Request a correction. Read our editorial standards and AI policy.
The Daily Brief
The technology briefing for people running businesses.
Weekdays at 6 a.m. ET. Free.


