The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors are actively exploiting critical vulnerabilities in core enterprise software from Microsoft, WSO2, and Adobe, putting thousands of organizations at immediate risk. The agency's alert, based on a report from BleepingComputer, confirms that attackers are leveraging these weaknesses in the wild, making patching an urgent priority.

The most dangerous threat involves a flaw chain in WSO2's identity and access management software. Researchers highlight that CVE-2026-5430, an authentication bypass, can be chained with CVE-2026-5431, an arbitrary file upload vulnerability. This combination grants remote attackers complete control over affected systems by first bypassing authentication and then deploying malicious files, a sequence that enables full system compromise.

Simultaneously, CISA has added a significant authentication bypass flaw in Microsoft SharePoint (CVE-2026-32568) to its Known Exploited Vulnerabilities catalog. As a platform central to corporate collaboration and document management, its compromise offers attackers a potent foothold for data theft and lateral movement within a network.

A third actively exploited vulnerability, an improper access control issue in Adobe Commerce (CVE-2026-32555), threatens e-commerce platforms, potentially allowing attackers to hijack backends.

Given the confirmed exploitation, CISA outlines critical interim measures for organizations unable to deploy patches immediately. For WSO2 systems, administrators should isolate the management console by restricting network access to trusted internal IPs only. For unpatched SharePoint servers, immediate isolation from the public internet and close monitoring are recommended.

The targeting of these specific platforms underscores a strategic threat. Identity systems like WSO2 and collaboration hubs like SharePoint are high-value targets; their breach grants attackers privileged access and a direct path to escalate privileges across an entire enterprise.

Administrative Action Checklist: 1. WSO2 (Priority): Apply vendor patches for CVE-2026-5430 and CVE-2026-5431 without delay. If patching is delayed, enforce strict network segmentation. 2. SharePoint: Update all servers to remediate CVE-2026-32568. Audit user permissions and scrutinize access logs for anomalous administrative activity. 3. Adobe Commerce: Patch instances to fix CVE-2026-32555 and prevent unauthorized access. 4. Posture Review: Scan networks for indicators of compromise related to these CVEs and review logs for signs of privilege escalation or data exfiltration.

CISA's advisory is a clear directive: these vulnerabilities are being exploited, and the window for remediation is now. Organizations relying on these foundational systems must treat this as a critical operational priority.


美國網絡安全和基礎設施安全局(CISA)發出警告,指出威脅行為者正在積極利用微軟、WSO2及Adobe核心企業軟件中的關鍵漏洞,令數千個組織面臨即時風險。該機構基於BleepingComputer報導的警報確認,攻擊者已在實際攻擊中利用這些弱點,因此修補漏洞成為當務之急。

最危險的威脅涉及WSO2身份和訪問管理軟件中的漏洞鏈。研究人員強調,CVE-2026-5430(身份驗證繞過漏洞)可與CVE-2026-5431(任意檔案上傳漏洞)結合利用。這種組合使遠端攻擊者能先繞過身份驗證,再部署惡意檔案,從而完全控制受影響系統,實現全面系統入侵。

與此同時,CISA已將Microsoft SharePoint的重大身份驗證繞過漏洞(CVE-2026-32568)加入其已知被利用漏洞目錄。作為企業協作和文檔管理的核心平台,其遭入侵將為攻擊者提供數據竊取和網絡橫向移動的強大立足點。

第三個被積極利用的漏洞是Adobe Commerce(CVE-2026-32555)的存取控制不當問題,威脅電子商務平台,可能允許攻擊者劫持後台系統。

鑑於漏洞已被證實遭利用,CISA為無法立即部署修補程式的組織概述了關鍵過渡措施。對於WSO2系統,管理員應透過限制網絡訪問至受信任的內部IP來隔離管理控制台。對於未修補的SharePoint伺服器,建議立即與公共互聯網隔離並密切監控。

這些特定平台成為攻擊目標,凸顯了戰略性威脅。像WSO2這樣的身份系統和像SharePoint這樣的協作中心都是高價值目標;其遭入侵將賦予攻擊者特權存取權限,並在整個企業內進行權限提升的直接途徑。

管理行動清單: 1. WSO2(優先): 立即套用供應商針對CVE-2026-5430和CVE-2026-5431的修補程式。若延遲修補,則強制執行嚴格的網絡分段。 2. SharePoint: 更新所有伺服器以修復CVE-2026-32568。審計用戶權限並仔細檢查訪問日誌,尋找異常管理活動。 3. Adobe Commerce: 為實例打補丁以修復CVE-2026-32555,防止未經授權的訪問。 4. 安全態勢審查: 掃描網絡以查找與這些CVE相關的入侵指標,並審查日誌以發現權限提升或數據外洩的跡象。

CISA的公告是一項明確指令:這些漏洞正被利用,修復窗口期已至。依賴這些基礎系統的組織必須將其視為關鍵的運營優先事項。

新聞來源 / Original News Source