Exploits Unleashed: CISA Adds More Headaches to Vulnerability Catalog!
CISA has added Microsoft WSUS and Adobe Commerce flaws to its Known Exploited Vulnerabilities catalog. Among them, the SessionReaper flaw is wreaking havoc on e-commerce sites. With only 38% of stores patched, it’s like leaving your front door open during a neighborhood-wide game of capture the flag, but with hackers instead of kids.

Hot Take:
Guess what? The digital world has a new episode of “Patch or Perish!” This time, starring everyone’s favorite software platforms, Microsoft WSUS and Adobe’s e-commerce twins, Commerce and Magento. Will they manage to fix their flaws before the hackers swoop in, or is this just another season of “The Vulnerable Strikes Back”? Stay tuned, folks!
Key Points:
- CISA adds Microsoft WSUS and Adobe Commerce & Magento flaws to its Known Exploited Vulnerabilities catalog.
- Adobe flaw, CVE-2025-54236, allows hijacking of customer accounts via the REST API.
- Microsoft WSUS vulnerability, CVE-2025-59287, enables unauthorized code execution over a network.
- Only 38% of affected Adobe stores are patched, with over 250 attacks in 24 hours.
- Federal agencies must address these vulnerabilities by November 14, 2025.
Already a member? Log in here
