The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical WSO2 authentication bypass and a high-severity Adobe flaw to its Known Exploited Vulnerabilities (KEV) catalog, creating an urgent, worldwide patching mandate for organizations using the affected software. This move elevates the vulnerabilities from a routine update to a top-priority security event.

The most severe flaw, tracked as CVE-2026-5430, holds a maximum CVSS score of 10.0. This authentication bypass affects a wide range of WSO2's enterprise integration and API management products, granting attackers a direct route to system compromise. Given the platform's widespread deployment, this vulnerability presents a high-value target for adversaries seeking to infiltrate networks.

The catalog also includes a critical vulnerability impacting Adobe Acrobat and Reader, software ubiquitous across professional and creative workflows. The specific CVE for the Adobe flaw was not detailed in the source reporting, but its inclusion in the KEV catalog indicates active exploitation, with potential consequences including data theft or broader network compromise.

While CISA's binding operational directive legally requires U.S. federal agencies to remediate these issues by specified deadlines, its KEV catalog functions as a de facto global benchmark for critical cybersecurity hygiene. Security teams across all sectors and geographies are strongly advised to treat the mandated timelines as a critical window for risk reduction.

Security experts recommend that organizations follow a standard incident response approach: inventorying all systems running affected software versions, applying vendor patches immediately, and reviewing logs for indicators of compromise (IOC) associated with these CVEs. The WSO2 flaw, given its perfect severity score and evidence of active exploitation, warrants the highest remediation priority.

The inclusion of these flaws in the KEV catalog confirms that adversaries have actively weaponized these weaknesses. Organizations relying on WSO2 or Adobe PDF tools must treat this as a critical security incident. Delaying remediation dramatically extends the window for attackers to execute disruptive or financially damaging operations.

For detailed technical guidance, teams should consult the official advisories from WSO2 and Adobe. The CISA KEV catalog entry itself provides the authoritative reference for tracking remediation deadlines.


美國網絡安全及基礎設施安全局(CISA)已將一個關鍵的 WSO2 認證繞過漏洞及一個嚴重程度較高的 Adobe 漏洞,納入其「已知被利用漏洞目錄」(KEV),這意味著所有使用受影響軟件的組織須在全球範圍內緊急進行修補。此舉將這些漏洞從一般性更新提升至首要安全事件的層級。

最嚴重的漏洞編號為 CVE-2026-5430,CVSS 評分達到最高級別 10.0。此認證繞過漏洞影響 WSO2 大量企業整合及 API 管理產品,攻擊者可藉此直接入侵系統。鑑於 WSO2 平台部署廣泛,此漏洞為企圖滲透網絡的攻擊者提供了一個高價值目標。

目錄同時收錄了一個影響 Adobe Acrobat 及 Reader 的嚴重漏洞,該軟件在專業及創意工作流程中被廣泛使用。來源報導並未詳列 Adobe 漏洞的具體 CVE 編號,但其被納入 KEV 目錄表明正遭活躍利用,可能導致數據外洩或更廣泛的網絡入侵。

雖然 CISA 的具約束力操作指令在法律上要求美國聯邦機構須在指定期限內修復這些問題,但其 KEV 目錄實際上已成為全球關鍵網絡安全標準的參考基準。各行業及地區的安全團隊均強烈建議將規定的時間表視為降低風險的關鍵窗口。

網絡安全專家建議,組織應遵循標準的事件響應流程:盤點所有運行受影響軟件版本的系統、立即套用供應商提供的修補程式,並檢查日誌中是否存有與這些 CVE 相關的入侵指標(IOC)。鑑於 WSO2 漏洞的最高嚴重性評分及其正遭活躍利用的證據,其修補工作應獲最高優先級。

這些漏洞被納入 KEV 目錄,證實攻擊者已積極將這些弱點武器化。依賴 WSO2 或 Adobe PDF 工具的組織必須將此視為關鍵安全事件。延遲修補將大幅延長攻擊者執行具破壞性或造成財務損失操作的窗口。

技術團隊應參閱 WSO2 及 Adobe 的官方安全通告以獲取詳細技術指引。CISA KEV 目錄的相關條目本身即為追蹤修補期限的權威參考資料。

新聞來源 / Original News Source