WSO2 and Adobe Commerce flaws are being exploited in attacks.
The WSO2 bug can lead to remote code execution through unrestricted file upload. The Adobe flaw can switch a customer session to another account. CISA has added both to KEV, with federal agencies given until Sept. 27 to patch.
What attackers can exploit: