Summary
CISA has added three critical vulnerabilities affecting Microsoft SharePoint, WSO2 API Manager, and Adobe Commerce to its Known Exploited Vulnerabilities catalog. CVE-2026-37985 is a pre-authentication RCE in SharePoint Server (CVSS 9.8). CVE-2026-28401 is an authentication bypass in WSO2 API Manager (CVSS 9.1). CVE-2026-34110 is a server-side template injection in Adobe Commerce (CVSS 9.0) allowing unauthenticated RCE. CISA has set a September 26, 2026 deadline for federal agencies to patch or mitigate all three.
Timeline
| Date | Event |
|---|---|
| Prior to Sep 24, 2026 | All three CVEs exploited in active campaigns; vendors patch and disclose |
| Sep 24-25, 2026 | CISA adds all three to KEV with September 26 federal deadline |
What Happened
CVE-2026-37985 is a pre-authentication deserialization vulnerability in SharePoint Server’s business data connectivity service. An unauthenticated attacker can send a crafted HTTP request triggering arbitrary code execution. Microsoft has released an out-of-band patch.
CVE-2026-28401 is an authentication bypass in WSO2 API Manager’s administrative console allowing unauthenticated access to management functions including API configuration, user management, and credential stores. Attackers can extract API credentials and modify routing configurations.
CVE-2026-34110 is a server-side template injection in Adobe Commerce (Magento) exploitable through storefront mechanisms without authentication, achieving code execution on Commerce servers that typically hold payment integrations, customer PII, and order histories. Adobe has released patches.
Note on Domain Intelligence
Three separate vendors are subject to this bulletin. Domain intelligence for microsoft.com, wso2.com, and adobe.com is available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 25, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026