Daily Top · Vulnerabilities / Identity

CISA put WSO2 on KEV. The catalog row says path traversal. WSO2 says JWT.

CVE-2026-5430 is CWE-347, not a file-upload RCE. Catalog 2026.09.24, due 27 September. watchTowr had admin JWTs on 13 September.

RWP Ventures · 2026-09-25 · event 2026-09-24 · 14 min read · priority 8.8

Bottom line up front

CONFIRMED CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog on 24 September 2026. Catalog version 2026.09.24 (released 24 September 19:00 UTC, count 1723). Two new rows since [yesterday’s WordPress Daily Top](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/). Federal due date is 27 September 2026. Ransomware-campaign use is Unknown. Forensic triage is Yes. CISA-ADP SSVC on the NVD record, stamped 24 September 00:00 UTC: exploitation active, automatable yes, technical impact total.

The product set is WSO2 API Manager, API Control Plane, Traffic Manager, and Universal Gateway. The vendor bug is not a path traversal. WSO2-2026-5328 (published 3 May 2026) and the WSO2 CNA record are CWE-347: JWT authentication accepts a token signed with an unsupported algorithm, then treats it as valid. Vendor score is 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, adjusted to 9.8 with S:U on single-tenant deployments. Unauthenticated account takeover, including administrative accounts.

Do not collapse three facts.

  1. CISA’s KEV title does not match the vendor primitive. The JSON row is named “WSO2 Multiple Products Path Traversal Vulnerability.” The short description talks about unrestricted file upload and remote code execution. The same row lists CWE-347. WSO2’s advisory, the CVE.org description, and NVD all describe JWT algorithm mismatch. Hunt and ticket against the vendor bug. A scanner looking for a Magento-style file write will miss this.
  2. The patch is months old. The catalog row is not. WSO2 says support-subscription holders apply a listed update level. SecurityWeek restated that WSO2 patched in April; the public advisory is 3 May; the CVE record is 6 August. watchTowr’s honeypots logged forged JWTs with administrator privileges on 13 September. CISA’s add is 24 September. A box that was “current in March” is not this close.
  3. Honeypot traffic is not a victim list. watchTowr (Yordan Ganchev) reported a single attacker hitting the wrong product; replaying the payload on API Manager worked. CISA’s KEV criterion is evidence of exploitation, not a named breach. Named victims remain UNKNOWN.

This is not a re-run of [yesterday’s WordPress Core include](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/). Different vendor, different plane, different clock. [F5 APM CVE-2026-94127](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/) is due today.

FactRecord
CVECVE-2026-5430
ProductWSO2 API Manager 4.1.0–4.6.0; API Control Plane 4.5.0/4.6.0; Traffic Manager 4.5.0/4.6.0; Universal Gateway 4.5.0/4.6.0
Vendor advisoryWSO2-2026-5328 (3 May 2026)
Vendor scoreCVSS 3.1 10.0 (9.8 single-tenant)
CWE (vendor / NVD / KEV row)CWE-347
KEV catalog2026.09.24, count 1723
Added / due24 September / 27 September 2026
ExploitationCONFIRMED as KEV; watchTowr honeypot JWTs 13 Sep
Ransomware useUnknown
Named CISA actorNone
OT / process impactNone claimed

What happened

CISA’s 24 September alert names two CVEs. The JSON freeze we retrieved is catalog 2026.09.24, dateReleased 2026-09-24T19:00:55Z, count 1723 (yesterday’s WordPress Daily Top froze 2026.09.23 at 1721). The 5430 row: vendor WSO2, product “Multiple Products,” due 27 September, ransomware Unknown, forensic triage Yes. Notes point at WSO2-2026-5328, BOD 26-04, and NVD.

WSO2’s own advisory is the technical record:

ProductVersionUpdate level
API Control Plane4.6.022
API Control Plane4.5.058
API Manager4.6.021
API Manager4.5.057
API Manager4.4.072
API Manager4.3.0108
API Manager4.2.0197
API Manager4.1.0257
Traffic Manager4.6.021
Traffic Manager4.5.056
Universal Gateway4.6.021
Universal Gateway4.5.057

NVD last-modified 25 September 04:17 UTC restates the same trains as CPE ranges (for example API Manager 4.1.0 before 4.1.0.257). NVD also lists WSO2 Carbon API Manager Rest API Utility CPEs that the vendor table does not name. Treat the vendor update-level table as the patch instruction; treat extra Carbon CPEs as ASSESSED in-scope via NVD, not as a second WSO2 advisory.

watchTowr is the public exploitation clock, published 16 September, now a week behind the catalog row:

The Hacker News (25 September) and Cyber Daily (25 September) independently restated the KEV add against that 13 September watchTowr window. CISA’s alert does not cite watchTowr. Do not write CISA’s unpublished evidence as watchTowr’s.

The other new row in the same freeze is CVE-2026-71362, Adobe Commerce / Magento incorrect authorization, due the same day. It is sequenced below. It is not this Daily Top.

Why it matters

WSO2 API Manager is the box that decides who may call which API, and often the box that holds the consumer keys for those calls. A JWT the product should have rejected, accepted as an administrator, is not “an auth library bug.” It is the identity plane of the integration layer.

Two operational lies will show up in tickets this weekend:

  1. “CISA said path traversal, we grepped uploads.” The catalog title and short description are the wrong primitive. The CWE on the same JSON object is 347. If your KEV workflow keys off CISA’s vulnerabilityName string, you will hunt a file-write that the vendor never described. Inventory JWT validation, admin sessions, and consumer-key access — then still apply the update level.
  2. “We patched WSO2 in the spring.” April/May’s fix exists. watchTowr’s September tokens, and CISA’s 24 September row, are what you are answering. Update level on the running train is the close, not the date you last opened a WSO2 ticket.

CISA-ADP’s SSVC triple — active, automatable, total — is why the due date is three days. BOD 26-04’s forensic-triage flag means the ticket is not closed when the update-level integer ticks. A gateway that has been accepting forged admin JWTs since mid-September may already have issued or copied credentials. The patch does not rewind that.

No public victim count. CISA, WSO2, watchTowr, The Hacker News, SecurityWeek, and Cyber Daily do not name an actor, a ransomware affiliate, or a confirmed customer breach. Cyber Daily’s earlier 16 September piece noted WSO2’s own customer count (on the order of a thousand, across banking, government, telecom, and logistics, in 90-plus countries) as product exposure, not as a victim list. RWP is not treating named logos in secondary reporting as compromises.

Internet-facing API Manager is the practical condition. SSVC automatable yes is CISA-ADP’s statement, not a mass-scan census.

Who / what is affected

AssetWhat to assumeStatus
WSO2 API Manager 4.1.0 through 4.6.0 below the tabled update levelIn scopeCONFIRMED vendor
API Control Plane 4.5.0 / 4.6.0 below tableIn scopeCONFIRMED vendor
Traffic Manager 4.5.0 / 4.6.0 below tableIn scopeCONFIRMED vendor
Universal Gateway 4.5.0 / 4.6.0 below tableIn scopeCONFIRMED vendor
Same trains at or above the listed update levelVendor close for this CVECONFIRMED vendor
Carbon API Manager Rest API Utility (NVD CPE only)Possibly in scopeASSESSED via NVD; not in WSO2-2026-5328 product list
Multi-tenant vs single-tenantSame bug; CVSS 10.0 vs 9.8CONFIRMED vendor
Named victimsNone publishedUNKNOWN
OT / ICS / processNot claimedNo evidence
CISA ransomware fieldUnknownCONFIRMED catalog

Internet-reachable publisher/devportal/gateway endpoints on those trains are the inventory unit. That is configuration, not a JWT recipe.

Technical context

RWP is not reproducing token headers, algorithm names beyond the vendor’s “unsupported algorithm,” or request bodies.

What the primary records give defenders:

ATT&CK mapping for what is stated:

Follow-on that is not claimed: a named APT, ransomware-Known, confirmed credential theft at a named customer, or OT/process impact.

Threat / exploitation status

ClaimStatusBasis
In KEV, added 24 Sep, due 27 Sep, catalog 2026.09.24 count 1723CONFIRMEDCISA alert + JSON
Exploitation in the wildCONFIRMED as KEV criterionCISA; CISA-ADP SSVC active
Forged admin JWTs on honeypots from 13 SepCONFIRMED as watchTowr telemetryTHN 16 Sep; SecurityWeek; Cyber Daily
JWT algorithm-mismatch, CWE-347, CVSS 10.0 / 9.8CONFIRMEDWSO2-2026-5328; CVE.org; NVD
KEV title “path traversal” / file upload / RCECONFIRMED as CISA text; not the vendor primitiveJSON row vs WSO2 advisory
Victim count / actorUNKNOWNNo named set in CISA, WSO2, watchTowr
Ransomware useUnknownCatalog field
Forensic triage requiredYesCatalog field
SSVC active / automatable / totalCONFIRMED as CISA-ADP, 24 Sep stampNVD
OT / physical-process impactNot claimedNo evidence

High confidence on: CVE ID, KEV dates, due date, catalog version and count, CVSS 10.0/9.8, CWE-347, product and update-level table, forensic-triage flag, ransomware Unknown, the CISA-title vs vendor-primitive mismatch, watchTowr’s 13 September honeypot date. Moderate confidence that internet-reachable API Manager is the dominant real-world condition (SSVC automatable + product role; no public census). Low confidence on CISA’s unpublished exploitation evidence, on any victim identity, on whether CISA’s path-traversal sentence describes a second bug, and on whether the update level displaces credentials already copied.

What defenders should do

  1. Inventory the four product names and the update-level integer, not “we have WSO2.” API Manager / Control Plane / Traffic Manager / Universal Gateway, train, update level, and whether the publisher, devportal, or gateway is reachable from untrusted networks. Record internet exposure for BOD 26-04. NVD’s extra Carbon utility CPE is a second pass, not a substitute for the vendor table.
  1. Preserve, then patch, then assume the token was already accepted. Snapshot gateway/auth logs, admin-account lists, application consumer keys and secrets, and routing changes before you reboot onto the new update level. Apply the tabled update level or the community fix in WSO2-2026-5328. Confirm the running build is at or above that integer. CISA’s notes do not say the patch removes a foothold already taken.
  1. Hunt JWT acceptance, not a webshell. Unexpected administrator sessions, new admin users, consumer-key access that does not match a change ticket, gateway routing edits in the 13–24 September window. Tokens whose signing algorithm is not in your configured set are a human-review trigger. Do not close “no PHP in /tmp.” This is not [yesterday’s WordPress include](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/).
  1. Do not let the KEV title drive the scanner signature. If your KEV pipeline keys off “path traversal” or “unrestricted file upload,” add an exception that this row is CWE-347. Ticket the JWT configuration and the update level.
  1. Rotate what the gateway can mint. If the instance was internet-reachable and below the tabled update level after 13 September, rotate admin credentials, application consumer keys and secrets, and any backend credentials stored in the product. That is containment after a possible token accept, not a confirmation of breach.
  1. Sequence the rest of the federal list. Same catalog freeze: CVE-2026-71362 (Adobe Commerce / Magento APSB26-92, customer-session identity switch, CVSS 9.1, due 27 September; Adobe’s 18 August bulletin still says it is not aware of in-the-wild exploits; Sansec reported blocking attempts in August; The Hacker News cites Previdian one Australian IP on 10 September). Due today, already assessed: [F5 APM CVE-2026-94127](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/), [Check Point CVE-2026-85102](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/) and CVE-2026-93616, Arista VeloCloud CVE-2026-93952. [Zyxel CVE-2026-7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/) was due yesterday.

This is not an exploitation guide. Use WSO2’s update-level table.

RWP assessment

Score 8.8. Same-week KEV add, a three-day BOD 26-04 clock, unauthenticated administrative takeover on the API identity plane, and a catalog-title mismatch that will send scanners looking for the wrong artifact. That is the highest-leverage new row in catalog 2026.09.24.

It outranks CVE-2026-71362 (Adobe Commerce / Magento, same freeze, same due date, CVSS 9.1, customer-account identity switch) as a daily because WSO2’s primitive is administrative takeover of the API control plane, the vendor patch is months old with September honeypot traffic, and Magento’s August APSB26-92 was already in the StyleSmuggler sequence. Customer ATO is real. It is not “the gateway accepted an admin JWT.” It outranks a second day on [F5 94127](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/) because Friday’s due date is not a new technical finding. It outranks [WordPress CVE-2026-87902](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/) because that story shipped yesterday and is still not on KEV (2026.09.24 still has no 87902 row). It outranks JetBrains TeamCity CVE-2026-63077 ransomware-use coverage (BleepingComputer 24 September; KEV row still dated 5 August, ransomware Known) because that CVE has been catalogued since August; a secondary restatement is not a first KEV add. It outranks CCCS’s Roundcube CVE-2026-48842 exploitation notice and CISA/FBI’s 23 September ICS-integrator fact sheet (Weekly OT lane; no new CVE).

The failure mode to sand down is “KEV says path traversal” and its twin, “we patched WSO2 in May.” If the running update level is below the table and the gateway still validates JWTs, you are in CISA’s denominator. If you only grepped uploads, you inventoried the wrong bug.

What we are watching

Sources

Sources

  1. CISA — Adds two KEV including CVE-2026-5430
  2. CISA — KEV JSON feed catalog 2026.09.24
  3. CISA — Known Exploited Vulnerabilities Catalog
  4. CISA — BOD 26-04
  5. WSO2 — Security Advisory WSO2-2026-5328 / CVE-2026-5430
  6. CVE — CVE-2026-5430
  7. NVD — CVE-2026-5430
  8. The Hacker News — WSO2 and Adobe Commerce flaws added to CISA KEV
  9. The Hacker News — Active exploitation attempts target WSO2 JWT bypass
  10. SecurityWeek — Enterprises warned of attacks exploiting WSO2 vulnerability
  11. Cyber Daily — WSO2 API Manager vulnerability added to CISA KEV
  12. Adobe — APSB26-92 Adobe Commerce / Magento
  13. CVE — CVE-2026-71362
  14. NVD — CVE-2026-71362
  15. Sansec — Adobe patches critical Magento account takeover APSB26-92
  16. CISA — Adds four KEV 22 September 2026