The U.S. Cybersecurity and Infrastructure Security Agency added a Microsoft SharePoint flaw and a MikroTik RouterOS flaw to its Known Exploited Vulnerabilities catalog on September 25, a day after listing critical WSO2 and Adobe Commerce flaws. CISA says all four have evidence of exploitation. Its federal remediation deadlines fall on September 27 and 28, giving affected agencies only days to address the exposure.

The new entries cover software used to manage enterprise content, APIs, online stores and network equipment. CISA sets a September 27 deadline for WSO2 CVE-2026-5430 and Adobe Commerce and Magento CVE-2026-71362, which it added on September 24. SharePoint CVE-2026-65660 and RouterOS CVE-2026-67279, added September 25, have a September 28 deadline. The agency has not identified the attackers or disclosed victim counts in its catalog.

WSO2 says CVE-2026-5430 affects API Manager, API Control Plane, Traffic Manager and Universal Gateway. Its advisory describes a JSON Web Token authentication bypass: a token signed with an unsupported algorithm can be accepted, potentially allowing administrative account takeover. CISA lists the same identifier with a different technical description, so operators should use the WSO2 advisory to identify affected versions and fixes. BleepingComputer reported that watchTowr observed forged-token attempts against a honeypot in September.

Adobe describes CVE-2026-71362 as a critical incorrect-authorization flaw in Commerce and Magento Open Source. Its August security bulletin rates it 9.1 on the CVSS scale and says exploitation requires neither authentication nor administrator privileges. The bulletin provides updated releases. CISA says the issue could give an attacker elevated access to sensitive resources without user interaction; its listing establishes the exploitation warning, while Adobe’s earlier bulletin did not report known exploitation at publication.

For the two September 25 additions, CISA says an authorized attacker could use SharePoint CVE-2026-65660 to execute code over a network. It says RouterOS CVE-2026-67279 could let an unauthenticated client open an SSH session channel and send an execution request, and could be chained with CVE-2026-86060. CISA lists no known ransomware campaign use for any of the four entries.

Organizations running these products should check the affected versions against vendor advisories, apply the available updates or mitigations, and review exposed systems for suspicious activity. CISA directs federal agencies to follow its current risk-based remediation guidance or discontinue use when mitigations are unavailable. The agency also urges asset owners to assess internet exposure as they prioritize the fixes.