SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026By Emandi Srinivas

Dataset Summary

FieldValueInterpretation
Reporting PeriodAugust 6 to September 24, 2026The two public CVE records were published on August 6 and August 11, 2026, and both vulnerabilities were added to CISA's KEV Catalog on September 24, 2026.
Data SourcesCISA KEV catalog and public CVE/NVD recordsThe timeline calculations use only dates established in the KEV and public CVE/NVD records. Dates that are not confirmed in those records are marked unavailable rather than inferred from secondary reporting.
Total CVEs Analyzed2CVE-2026-5430 and CVE-2026-71362.
Average Disclosure-to-Patch GapUnavailableThe allowed timeline dataset does not establish a separate, exact patch-availability date for both CVEs.
Average Patch-to-Exploitation GapUnavailableCISA KEV confirms known exploitation, but neither KEV nor the public CVE/NVD records establish an exact first-exploitation date for both cases.
Average Disclosure-to-KEV Gap46.5 calendar daysThe two consistently calculable intervals are 49 days for CVE-2026-5430 and 44 days for CVE-2026-71362.
Median Disclosure-to-KEV Gap46.5 calendar daysWith two observations, the median is the midpoint of 44 and 49 days; neither CVE has a 46.5-day interval.
Shortest / Longest Gap Observed44 days / 49 daysShortest disclosure-to-KEV interval: CVE-2026-71362. Longest: CVE-2026-5430.

Sourcing and Methodology Note

The timeline dataset is drawn from the CISA Known Exploited Vulnerabilities Catalog and the public CVE/NVD records for CVE-2026-5430 and CVE-2026-71362. CISA's September 24, 2026 alert confirms that both vulnerabilities were added to KEV based on evidence of active exploitation. Public CVE/NVD publication dates provide the disclosure dates used in the calculations.

SecPod's analytical layer is separate from the underlying public data. The calendar-day differences, averages, median, range, comparisons, and operational interpretation in this article are SecPod calculations derived from the cited public dates; they are not statistics published by CISA, the CVE Program, or NVD.

Supplemental primary records were checked only to validate technical wording and remediation context, not to supply timeline calculation dates. These include WSO2 Security Advisory WSO2-2026-5328, the WSO2-linked GitHub fix record, Adobe Security Bulletin APSB26-92, and CISA BOD 26-04. WSO2's advisory links a public fix pull request that GitHub records as merged on April 12, 2026, but that code-history milestone is not used as the cohort's patch date because it does not establish the exact supported-update availability date across every affected WSO2 product. Adobe's bulletin and the public CVE/NVD record confirm the August 2026 unaffected update levels for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source.

Technical-source conflict: CISA's KEV title and short description for CVE-2026-5430 describe a path-traversal/file-upload issue, while the WSO2 and public CVE/NVD record describe a JWT authentication-bypass condition caused by improper verification of the signing algorithm. This article uses the WSO2/CVE technical description for the vulnerability while retaining CISA as the authority for KEV status and the September 24 catalog-addition date.

The term mass exploitation is not used. KEV inclusion establishes known exploitation but does not provide an exact first attack date, victim count, or campaign start date. Third-party exploitation observations are therefore excluded from the timeline calculations.

Introduction

This analysis covers two critical vulnerabilities whose public CVE records were published between August 6 and August 11, 2026 and which CISA added together to KEV on September 24, 2026. The consistently measurable disclosure-to-KEV intervals are 49 days for CVE-2026-5430 and 44 days for CVE-2026-71362, while an exact cohort-wide patch-to-first-exploitation gap cannot be calculated from the permitted timeline sources. Operationally, that distinction matters because KEV inclusion confirms exploitation but should not be treated as the first attack date or as a substitute for a separately verified patch-availability timestamp.

Background and Context

The disclosure-to-patch-to-exploitation sequence is tracked because each interval answers a different defensive question: when the vulnerability became publicly known, when a deployable fix was available, and how much time defenders had before exploitation was observed. Keeping those events separate prevents a catalog-addition date or advisory date from being misread as an attacker timeline.

A directly comparable prior-period dataset using the same date-selection rules is not established for this analysis, so the September 24 cohort cannot be described as widening, narrowing, or stable relative to earlier periods. The two-CVE sample is also too small to support a defensible comparison by vendor, product type, or vulnerability class.

The source material confirms active exploitation for both CVEs, but it does not establish a broader shift in attacker behavior or disclosure practice for this reporting period. Both vulnerabilities are critical and remotely reachable according to their public CVE records, yet the available evidence does not provide a common first-exploitation date that could be used to infer a change in attacker speed.

Gap Calculation Methodology

Disclosure (D): the public CVE/NVD publication date used for the record: for CVE-2026-5430 and for CVE-2026-71362.

Patch Available (P): the earliest exact patch-availability date confirmed in the allowed KEV/CVE/NVD timeline dataset. Where the record lists remediation or unaffected versions but does not separately establish the date those fixes became available, P is marked unavailable rather than inferred.

First Exploitation (E): the earliest exact exploitation date confirmed in the allowed KEV/CVE/NVD timeline dataset. KEV inclusion establishes known exploitation but does not itself establish the first day of exploitation, so E is unavailable for both CVEs.

KEV Added (K): CISA's dateAdded value, for both vulnerabilities.

Disclosure-to-Patch = P - D

Patch-to-First-Exploitation = E - P

Disclosure-to-KEV = K - D

No CVE is excluded from the cohort. Both CVEs are excluded only from disclosure-to-patch and patch-to-first-exploitation aggregate calculations because the required exact P and E dates are not established in the permitted timeline sources. The April 12 WSO2 GitHub merge is retained as supplemental code-history context outside the calculation, and third-party Adobe/WSO2 exploitation observations are not converted into first-exploitation dates.

Patch Timeline & Exploitation Gap Analysis

The full-cohort metric that can be calculated consistently is the interval from public CVE disclosure to KEV inclusion. The two values are 44 and 49 calendar days, producing an average and median of 46.5 days and a five-day range.

Aggregate MetricCohort Result
Total CVEs2
Published Severity BandBoth Critical; no cross-severity-band comparison is possible
Disclosure-to-KEV Distribution44 and 49 calendar days
Average Disclosure-to-KEV Gap46.5 calendar days
Median Disclosure-to-KEV Gap46.5 calendar days
Disclosure-to-KEV Range5 calendar days
Disclosure-to-Patch GapUnavailable for full-cohort calculation
Patch-to-First-Exploitation GapUnavailable for full-cohort calculation

Because both CVEs fall in the critical severity band and the dataset contains only two observations, this cohort cannot establish whether exploitation timing varies by CVSS severity. The same limitation prevents a defensible aggregate conclusion by vulnerability class or platform type.

CVE Timeline Data

CVE IDDisclosure DatePatch AvailableKEV Added / First ExploitationDays: Disclosure → PatchDays: Patch → Exploitation
CVE-2026-5430 Unavailable as a separately dated patch-availability event in the KEV/CVE/NVD timeline dataset. KEV added; exact first-exploitation date unavailable. Unavailable Unavailable
CVE-2026-71362 Unavailable as a separately dated patch-availability event in the KEV/CVE/NVD timeline dataset. KEV added; exact first-exploitation date unavailable. Unavailable Unavailable

Statistical Distribution and Outliers

The measurable disclosure-to-KEV values are 44 and 49 days. Their 46.5-day mean and median sit exactly between the two observations, and the five-day range indicates that the two listing intervals are close to one another.

Neither CVE should be described as a statistical outlier. With only two observations, the dataset is too small to establish a stable distribution or a meaningful outlier threshold.

The unavailable patch and first-exploitation dates form a separate limitation rather than missing values to be estimated. They are not replaced with vendor-advisory dates, code-merge dates, third-party reporting dates, or KEV inclusion dates.

Vulnerability Class Breakdown

CVEVulnerability Class / CWEPublished Severity ContextDisclosure-to-KEV
CVE-2026-5430JWT authentication bypass / Improper Verification of Cryptographic Signature; CWE-347Critical; CVSS v3.1 10.0 in the scope-changing scenario and 9.8 in single-tenant deployments49 days
CVE-2026-71362Incorrect Authorization; CWE-863Critical; CVSS v3.1 9.144 days

There is only one example in each weakness class, so no class-level timing conclusion is supported. The same limitation applies to product type, and the cohort provides no cross-severity-band comparison because both vulnerabilities are rated critical.

Notable Case Highlights

CVE-2026-71362: a 44-day CVE-publication-to-KEV interval. The public CVE/NVD record was published on August 11, 2026 and CISA added the vulnerability to KEV on September 24, producing a 44-day interval. Adobe's APSB26-92 and the public CVE/NVD record confirm the August 2026 unaffected update levels for Adobe Commerce 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.6 through 2.4.9. Earlier third-party exploitation reporting is not used because it does not establish a first-exploitation date in the KEV/CVE/NVD timeline dataset.

CVE-2026-5430: a 49-day CVE-publication-to-KEV interval with earlier code-fix history kept separate. The public CVE record was published on August 6, 2026 and CISA added the vulnerability to KEV on September 24, producing a 49-day interval. WSO2's advisory links a public GitHub fix, and the referenced pull request shows a merge date of April 12, 2026. That date is a verified code-history milestone, but it is not treated as the cohort patch-availability date because the permitted timeline dataset does not establish the corresponding supported-update availability date across every affected WSO2 product.

Historical Trend Comparison

A prior-period dataset using the same date-selection rules was not established for this analysis. Consequently, this post does not label the observed disclosure-to-KEV gap as widening, narrowing, or stable.

A defensible future comparison would need the same public-CVE disclosure rule, the same treatment of unavailable patch and first-exploitation dates, and the same separation between first exploitation and KEV inclusion. Mixing unlike milestones across periods would measure different events and could create a trend that is not present in the source data.

MITRE ATT&CK Mapping

The public records support only a high-level analytical mapping to exploitation of an externally reachable application. This is SecPod's analytical mapping rather than an ATT&CK mapping published by CISA, and no broader post-exploitation tactic chain is asserted from the available evidence.

TacticTechniqueID
Initial AccessExploit Public-Facing ApplicationT1190

Risk Context for Organizations

The measurable 44-day and 49-day disclosure-to-KEV intervals describe how long the public CVE records existed before CISA added the vulnerabilities to KEV. They are not safe waiting periods, patching service levels, or estimates of how long attackers waited before exploitation.

CISA's BOD 26-04 prioritization framework evaluates asset exposure, KEV status, exploit automation, and technical impact. For the September 24 additions, CISA's alert specifically emphasizes rapid remediation of KEV vulnerabilities on publicly exposed assets that grant total control after exploitation and establishes expectations for compromise checks in applicable cases. Those federal requirements apply to in-scope Federal Civilian Executive Branch agencies; other organizations can use the same risk signals without treating the federal timeline as a universal legal deadline.

KEV inclusion confirms known exploitation but does not establish when exploitation started. Because the allowed dataset does not provide an exact first-exploitation day for either CVE, this article does not quantify an exploitation-to-KEV warning interval.

Detection and Patch Prioritization Considerations

Match exposure and applicability to the current product record. For WSO2, technical detection and remediation logic should follow the JWT authentication-bypass description in the WSO2/CVE record rather than the conflicting path-traversal wording in the KEV short description. For Adobe, applicability should be matched to the affected product family and branch identified in the public CVE/NVD record.

Prioritize exposed, high-impact systems without turning CVSS into a timing assumption. Both CVEs are critical and network reachable, but the source data does not supply a reliable first-exploitation clock. Exposure, business criticality, KEV status, and the consequences of successful exploitation should therefore inform prioritization together.

Verify deployment separately from publication. A public remediation record or unaffected-version entry does not prove that every affected system received the fix on the same day. Patch-management records should preserve the actual deployment date for each asset so source publication and organizational remediation are not conflated.

Keep compromise assessment separate from patch validation. Applying the relevant update closes the known vulnerability but does not by itself establish that the system was not accessed earlier. Where exposure and CISA guidance warrant it, compromise review should proceed as a separate defensive activity.

Key Takeaways

  • CVE-2026-5430 and CVE-2026-71362 were added to CISA KEV on September 24, 2026 after public CVE publication on August 6 and August 11, respectively.
  • The consistently measurable disclosure-to-KEV intervals are 49 days for WSO2 and 44 days for Adobe, producing a 46.5-day mean and median.
  • A cohort-wide disclosure-to-patch or patch-to-first-exploitation gap is unavailable because the required exact patch and first-exploitation dates are not established in the permitted KEV/CVE/NVD timeline sources.
  • The April 12 WSO2 code-fix merge is verified but retained only as supplemental context; it is not generalized into a supported-update availability date across every affected WSO2 product.
  • CISA's technical short description for CVE-2026-5430 conflicts with the WSO2/CVE record, so technical detection and remediation should follow the JWT authentication-bypass record while KEV remains the source for known-exploitation status.

Conclusion

The September 24 KEV pair shows a closely grouped disclosure-to-listing pattern: 44 and 49 days from public CVE publication to CISA KEV inclusion. What the public timeline does not establish is equally important: an exact, comparable patch-availability date and first-exploitation day for both vulnerabilities.

For vulnerability and patch management programs, disclosure, patch availability, exploitation evidence, KEV inclusion, and actual deployment should remain separate records. Keeping those events distinct makes the analysis reproducible without turning code history, secondary reporting, or catalog dates into timeline facts that the primary dataset does not establish.

Constantly Fix Risks with Saner Patch Management

Saner Patch Management is a continuous, automated, and integrated patch management solution that helps organizations identify, prioritize, and remediate vulnerabilities actively exploited in the wild. It supports Windows, Linux, macOS, and more than 550 third-party applications, enabling timely deployment of security updates across enterprise environments.

The platform also provides safe patch testing environments, automated deployment workflows, compliance reporting, and patch rollback capabilities to minimize operational risk while ensuring critical vulnerabilities are addressed without delay.

Experience the fastest and most accurate patching software here.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026

Open Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited
Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

CVE Research

Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

Citrix has released security updates for NetScaler ADC and NetScaler Gateway addressing CVE-2026-88771 and CVE-2026-88772, two critical remote code execution vulnerabilities. Exploits against unmitigated deployments have been observed. CVE-2026-88771 affects all deployments, including default configurations; CVE-2026-88772 applies when DTLS is enabled, including the default state on VPN virtual servers. This article covers impact, affected and fixed versions, how to confirm exposure, and recommended remediation.

Sep 28, 2026