A cluster of cybersecurity warnings emerged Thursday, with the Cybersecurity and Infrastructure Security Agency adding four vulnerabilities to its Known Exploited Vulnerabilities catalog, while software company Kiteworks separately urged customers to take systems offline over a potential zero-day threat flagged by federal intelligence authorities.
CISA's additions to the KEV catalog span products from WSO2, Adobe, Microsoft, and Mikrotik, each confirmed as being actively leveraged in attacks against enterprise targets.
The most severe of the four is CVE-2026-5430, a maximum-severity authentication bypass flaw in WSO2 products, including API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0. The flaw stems from the platform's JWT authentication mechanism accepting tokens signed with an unsupported algorithm, which an attacker can exploit to compromise administrative accounts and assume full control of affected systems, according to a vendor advisory published May 3.
Security firm watchTowr announced on September 15 that its honeypots had captured exploitation attempts as early as September 13, originating from a single IP address using forged JWT tokens. The attacker targeted the wrong product variant, but watchTowr confirmed that forged tokens could expose API endpoints and application credentials on the correct target.
Yordan Ganchev, threat intelligence specialist at watchTowr, told BleepingComputer that WSO2 is not a niche target. "Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics," Ganchev said. "Organizations in these sectors can't afford to wait for exploitation to be formally confirmed."
Also added to the KEV catalog is CVE-2026-71362, a critical incorrect authorization vulnerability affecting Adobe Commerce and Magento e-commerce platforms. E-commerce security firm Sansec observed the flaw being exploited in the wild, noting that threat actors require "no existing account, administrator privileges, or user interaction" to leverage it.
Federal agencies using products affected by either critical flaw have until Sunday, September 27, to apply mitigations or discontinue use. For the remaining two additions — a high-severity code injection flaw in Microsoft SharePoint tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH bypass in Mikrotik RouterOS identified as CVE-2026-67279 — agencies have until Monday, September 28.
Separately, Kiteworks — the file transfer and secure communications platform formerly known as Accellion — sent customers an email this week recommending they shut down systems during a six-hour window on Saturday, citing credible threat intelligence from federal authorities.
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers." Balonis characterized the advisory as precautionary, stating the company was "not aware of any compromise of Kiteworks systems" and that all known vulnerabilities are addressed in the current release, version 9.5.1.
A Kiteworks customer support official told German outlet Heise, which first reported the customer email, that the warning was sent due to a potential zero-day vulnerability. The company did not respond to follow-up questions about whether the flaw has been assigned a CVE.
Jake Knott, a senior official at watchTowr, said his firm is actively tracking the threat but flagged the advisory as unusual. "There is no known CVE, patch, or additional technical details available — but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch," Knott said.
Knott also pointed to Kiteworks' history under the Accellion name, when Clop used a zero-day in December 2020 to steal data from dozens of organizations, including the University of Colorado, Flagstar Bank, and airplane maker Bombardier. "Attackers' appetites for targeting [managed file transfer] appliances has not" diminished, Knott said, adding that "this is familiar territory, but not the comforting kind."
The FBI declined to comment on the Kiteworks matter, and CISA did not respond to requests for comment. With the September 27 and 28 patch deadlines approaching and the Kiteworks situation still unresolved, security teams at organizations running any of the affected platforms face a compressed window to act.