CISA Flags WSO2 Security Flaw Under Active Exploitation
CISA added actively exploited WSO2 flaw CVE-2026-5430, a CVSS 10 path traversal and JWT bug, to KEV.
CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog on September 24, 2026, after evidence of active exploitation, and set a federal remediation deadline of September 27. The flaw affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. CISA describes a path traversal issue that can allow unrestricted file uploads and remote code execution. The CVE record also cites improper JWT signature verification, CWE-347, that can enable crafted tokens, administrative compromise, and full account takeover, with a CVSS v3.1 score of 10.0 in one scenario. Ransomware use is unknown, but BOD 26-04 requires forensic triage.