CISA Gives Federal Agencies Three Days to Patch a WSO2 Flaw Already Being Exploited
Two critical bugs are being actively exploited. Federal civilian agencies must fix the WSO2 vulnerability by September 27, and the same urgency applies to any organisation running the affected software.

Key points
- CISA added CVE-2026-5430, a critical WSO2 path traversal flaw, to its Known Exploited Vulnerabilities catalogue, giving federal agencies a tight remediation window.
- The bug scores 9.8 out of 10 for severity and lets an attacker forge login tokens to seize administrator accounts.
- A second flaw in Adobe Commerce and Magento was added to the same catalogue on the same day.
- Affected WSO2 products include API Manager, API Control Plane, Universal Gateway and Traffic Manager.
- CISA says both bugs are being used in active attacks, though the agency hasn't named victims or attackers.
The US Cybersecurity and Infrastructure Security Agency told federal civilian agencies on September 27 to patch two software flaws that criminals are already exploiting. That deadline is unusually short and signals CISA sees immediate risk, not a theoretical one.
We first reported active exploitation of CVE-2026-5430 on 17 September in "Attackers Are Actively Exploiting a Perfect-10 WSO2 Authentication Flaw", when exploitation had already been under way for four days. CISA's catalogue addition is the formal federal mandate that follows.
The agency added both vulnerabilities to its Known Exploited Vulnerabilities catalogue, a public list of bugs that attackers have been caught using in the wild. Private companies aren't bound by the deadline, but security teams treat the list as a priority queue.
What is the WSO2 flaw?
CVE-2026-5430 is a path traversal vulnerability in WSO2, an open-source platform companies use to run and secure internal software services. SOURCE scores it 9.8 out of 10 for severity. The flaw allows unrestricted file uploads and remote code execution, meaning an attacker can run their own commands on the server and take full control.
WSO2 also has a separate signature-verification weakness, documented in our earlier coverage, that lets attackers hand-craft fake JSON Web Tokens (small signed digital passes that prove a user is logged in) and walk in as an administrator. Both paths lead to the same outcome: full takeover.
The following WSO2 products are affected:
| Product | Flaw | Severity |
|---|---|---|
| WSO2 API Manager | CVE-2026-5430 | Critical (9.8) |
| WSO2 API Control Plane | CVE-2026-5430 | Critical (9.8) |
| WSO2 Traffic Manager | CVE-2026-5430 | Critical (9.8) |
| WSO2 Universal Gateway | CVE-2026-5430 | Critical (9.8) |
What about the Adobe Commerce bug?
CISA also added a separate incorrect authorization flaw in Adobe Commerce and Magento to the same catalogue. Both products power large numbers of online shops. An authorization bug of this kind typically lets an attacker read or modify data they shouldn't reach. CISA hasn't published details on who is exploiting it or how widely.
Should you worry?
Patch, and check whether attackers already got in. That's the instruction CISA is giving federal agencies, and it applies equally to any private company running the affected software.
WSO2 published fixes for CVE-2026-5430 when the flaw was disclosed on August 6, so the patch has been available for weeks. Any organisation that hasn't applied it should assume attackers have had time to notice and act. Adobe customers should apply the vendor's latest Commerce and Magento security update.
My read: the tight federal deadline is the tell here. CISA normally gives agencies three weeks. A three-day window means someone at the agency has seen exploitation they consider serious and spreading, and the WSO2 patch gap of nearly two months gave attackers plenty of runway to find unprotected targets.



