The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical WSO2 vulnerability (CVE-2026-5430) to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw in real-world attacks. The issue affects several WSO2 products used to manage APIs and gateway traffic. The vulnerability affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. It is a path traversal flaw that could allow an attacker to upload files to unintended locations on a vulnerable server. If exploited, the issue could allow unrestricted file uploads and remote code execution. Remote code execution is especially dangerous because it may allow a threat actor to run commands...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!