CISA KEV Alert 24 Sept 2026, 20:01 UTC

CISA Warns of Active Exploits Targeting Critical WSO2 Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities (KEV) catalogue on 24 September 2026. The vulnerability affects WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway. Known as the WSO2 Multiple Products Path Traversal Vulnerability, it could allow unrestricted file uploads and lead to remote code execution.

The flaw is a path traversal vulnerability affecting multiple WSO2 products. An attacker could exploit it to upload files without restriction, potentially achieving remote code execution. The vulnerability has a CVSS score of 10.0 and is rated Critical. The patch status is unknown, and no patch advisory was provided in the supplied data.

CISA’s KEV listing confirms that attackers are actively exploiting this vulnerability. Use in ransomware campaigns is unknown. Federal Civilian Executive Branch (FCEB) agencies must remediate CVE-2026-5430 by 27 September 2026.

CISA requires organisations to apply mitigations in accordance with WSO2’s instructions, while following CISA’s BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. For cloud services, organisations should follow the applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and comply with the relevant patching requirements. FCEB agencies are directly affected, but all organisations should review their exposure to the affected WSO2 products.

See the NVD entry for CVE-2026-5430 and CISA’s KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline