# CISA sets deadlines for agencies to address four exploited software flaws

_Published Friday, September 25, 2026 at 2:07 PM EDT · Security, Policy · Latest · Tier 2 — Notable_

![CISA sets deadlines for agencies to address four exploited software flaws — Primary](https://www.bleepstatic.com/content/hl-images/2026/07/22/CISA.jpg)

CISA has added exploited vulnerabilities affecting WSO2 products, Adobe Commerce, Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities catalog. Federal agencies using the affected products must apply recommended fixes or mitigations by September 27 for the WSO2 and Adobe flaws, and by September 28 for the SharePoint and RouterOS flaws.

The WSO2 authentication flaw could allow an attacker to compromise administrative accounts and take control, according to the vendor. The Adobe Commerce flaw affects authorization and has been observed in attacks without an existing account. CISA has not disclosed details of the attacks involving WSO2.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/)

---
Canonical: https://techandbusiness.org/newswire/aInIrT2F3UH2qb7TcfoHiU
Published: 2026-09-25T18:07:15.906Z
Story chronology: 2026-09-25T17:24:20.000Z
Retrieved: 2026-09-25T19:44:36.771Z
Publisher: Tech & Business (techandbusiness.org)
