CISA Warns of WSO2 Multiple Products Vulnerability Exploited in Attacks
CISA says attackers are exploiting WSO2 CVE-2026-5430, a path-traversal flaw that can lead to remote code execution.
CISA added WSO2 vulnerability CVE-2026-5430 to the Known Exploited Vulnerabilities catalog on September 24, 2026, citing active exploitation. The path-traversal flaw affects API Control Plane, API Manager, Traffic Manager, and Universal Gateway and can allow unintended file uploads and remote code execution. CISA catalogs it as CWE-347, improper verification of cryptographic signatures. Under BOD 26-04, federal civilian agencies must apply vendor mitigations by September 27, 2026, and conduct forensic triage; ransomware use has not been confirmed.
- CISA added CVE-2026-5430 to the KEV catalog on September 24, 2026.
- Path traversal may allow unrestricted file upload and remote code execution.
- API Manager, Control Plane, Traffic Manager, and Universal Gateway are affected.
- Federal agencies must mitigate by September 27 and perform forensic triage.
- CISA has not confirmed ransomware use of the flaw.
Vulnerabilities mentionedAll →
- CVE-2026-543010.0<1%Unauthenticated JWT Algorithm Bypass in WSO2 API Manager and Gatewayspublished · wso2 api manager KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-5430 |
Full article455 words · extracted from cybersecuritynews.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical WSO2 vulnerability (CVE-2026-5430) to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw in real-world attacks.
The issue affects several WSO2 products used to manage APIs and gateway traffic. The vulnerability affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway.
It is a path traversal flaw that could allow an attacker to upload files to unintended locations on a vulnerable server. If exploited, the issue could allow unrestricted file uploads and remote code execution.
Remote code execution is especially dangerous because it may allow a threat actor to run commands or deploy malicious tools on the affected system.
In an API management environment, a compromise could expose backend services, application credentials, API traffic, and other connected infrastructure. CISA listed the weakness under CWE-347, which relates to improper verification of cryptographic signatures.
WSO2 Vulnerability Exploited
Organizations should review the vendor’s security guidance carefully because the affected products may require more than a routine software update, depending on their configuration and deployment model.
The vulnerability was added to the Known Exploited Vulnerabilities catalog on September 24, 2026. Federal civilian executive branch agencies must apply vendor-recommended mitigations by September 27, 2026, under Binding Operational Directive 26-04.
CISA also requires forensic triage for affected environments, indicating that agencies should investigate whether compromise activity occurred before applying mitigations.
CISA has not confirmed whether CVE-2026-5430 has been used in ransomware campaigns. However, the agency’s inclusion of the flaw in the exploited-vulnerability catalog means defenders should treat exposed WSO2 systems as a high-priority risk.
Security teams should first identify all internet-facing and internally deployed WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway instances.
They should then apply the mitigations and updates WSO2 specifies. If mitigations are not available, organizations should consider removing affected systems from service until they can deploy a secure fix.
Forensic triage should include reviewing web-server logs, application logs, file-upload activity, newly created files, unexpected administrative accounts, suspicious child processes, and outbound network connections.
Teams should also check whether files were written outside approved upload directories, as this may indicate attempted path traversal exploitation.
Organizations using cloud-hosted WSO2 services should evaluate their exposure with the service provider and follow applicable cloud-service guidance under BOD 26-04.
CISA also advised stakeholders to assess every asset’s internet exposure and ensure patching decisions align with the directive’s risk-based security-update requirements.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.