Cyber & AI intelligence
Wasteland.
Briefs indexed2864
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-5430 2026-09-24

WSO2 API Platform Flaw CVE-2026-5430 Added to CISA KEV Under Active Exploitation

"CISA has added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog, confirming active exploitation of a critical (CVSS 10.0) flaw in several WSO2 API management products."

CISA has added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog, confirming active exploitation of a critical (CVSS 10.0) flaw in several WSO2 API management products.

What Is It

The CISA and NVD records describe CVE-2026-5430 in two different ways.

The two sources disagree on the weakness type. Defenders should read the WSO2 advisory (WSO2-2026-5328) for the vendor's own description.

Why It Matters

What's Vulnerable

According to NVD, these builds are affected:

Product Affected ranges
WSO2 API Manager 4.1.0 < 4.1.0.257; 4.2.0 < 4.2.0.197; 4.3.0 < 4.3.0.108; 4.4.0 < 4.4.0.72; 4.5.0 < 4.5.0.57; 4.6.0 < 4.6.0.21
WSO2 API Control Plane 4.5.0 < 4.5.0.58; 4.6.0 < 4.6.0.22
WSO2 Universal Gateway 4.5.0 < 4.5.0.57; 4.6.0 < 4.6.0.21
WSO2 Traffic Manager 4.5.0 < 4.5.0.56; 4.6.0 < 4.6.0.21

Patch Status

The upper bounds of the NVD ranges suggest which builds fix the flaw. For example, the NVD data implies that API Manager 4.6.0.21 and API Control Plane 4.6.0.22 are no longer affected. These fixed versions come from NVD's version ranges, not from vendor confirmation. NVD and CISA also describe the flaw differently, so it is unclear whether these builds fix every issue covered by the KEV entry. Check fixed versions and any extra mitigation steps against WSO2 advisory WSO2-2026-5328 before treating a system as remediated.

CISA's required action says to: - Apply mitigations according to vendor instructions. - Follow BOD 26-04, "Prioritizing Security Updates Based on Risk," and CISA's Forensics Triage Requirements. - Follow BOD 26-04 guidance for cloud services, or stop using the product if mitigations are not available. - Evaluate each asset's internet exposure.

Because CISA requires forensic triage, organizations should check exposed instances for signs of compromise as well as patching them.

Sources