TTO-2026-0925-165 · September 25, 2026 Active ExploitationCritical

CISA Adds SharePoint, WSO2 API Manager, and Adobe Commerce Zero-Days to KEV as Active Exploitation Confirmed

CVE-2026-37985 SharePoint CVSS 9.8CVE-2026-28401 WSO2 CVSS 9.1CVE-2026-34110 Adobe Commerce CVSS 9.0Three CISA KEV additionsSeptember 26 deadline

Summary

CISA has added three critical vulnerabilities affecting Microsoft SharePoint, WSO2 API Manager, and Adobe Commerce to its Known Exploited Vulnerabilities catalog. CVE-2026-37985 is a pre-authentication RCE in SharePoint Server (CVSS 9.8). CVE-2026-28401 is an authentication bypass in WSO2 API Manager (CVSS 9.1). CVE-2026-34110 is a server-side template injection in Adobe Commerce (CVSS 9.0) allowing unauthenticated RCE. CISA has set a September 26, 2026 deadline for federal agencies to patch or mitigate all three.

Timeline

DateEvent
Prior to Sep 24, 2026All three CVEs exploited in active campaigns; vendors patch and disclose
Sep 24-25, 2026CISA adds all three to KEV with September 26 federal deadline

What Happened

CVE-2026-37985 is a pre-authentication deserialization vulnerability in SharePoint Server’s business data connectivity service. An unauthenticated attacker can send a crafted HTTP request triggering arbitrary code execution. Microsoft has released an out-of-band patch.

CVE-2026-28401 is an authentication bypass in WSO2 API Manager’s administrative console allowing unauthenticated access to management functions including API configuration, user management, and credential stores. Attackers can extract API credentials and modify routing configurations.

CVE-2026-34110 is a server-side template injection in Adobe Commerce (Magento) exploitable through storefront mechanisms without authentication, achieving code execution on Commerce servers that typically hold payment integrations, customer PII, and order histories. Adobe has released patches.

Note on Domain Intelligence

Three separate vendors are subject to this bulletin. Domain intelligence for microsoft.com, wso2.com, and adobe.com is available at warmbadge.com.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 25, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026