Critical Path Traversal (CVE‑2026‑5430) in WSO2 API Control Plane Added to CISA KEV Amid Active Exploitation
What It Is — A high‑severity path‑traversal flaw (CVSS 9.8) in the WSO2 API Control Plane lets an unauthenticated attacker read arbitrary files on the host system. The vulnerability is tracked as CVE‑2026‑5430.
Exploitability — CISA’s Known Exploited Vulnerabilities (KEV) catalog now lists the flaw, confirming that threat actors are actively weaponising it in the wild. No public proof‑of‑concept is required; exploitation is already observed.
Affected Products —
- WSO2 API Control Plane (API management platform)
- Adobe Commerce / Magento (e‑commerce platform) – a separate critical flaw also added to KEV (details not disclosed in the source).
Why It Matters for Trust & Control Assurance
- Control Objective – Secure Configuration & Access Controls – The flaw demonstrates a gap in protecting critical service components from unauthorized file access, a control that maps to many frameworks (e.g., NIST CSF PR.IP‑1, ISO 27001 A.12.1).
- Continuous Monitoring – Detecting exploitation requires log‑based monitoring of file‑access patterns and API‑plane activity, providing defensible evidence for auditors.
- Due‑Diligence Evidence – Demonstrating timely patching and verification of remediation is a concrete trust signal for enterprise buyers and regulators.
Recommended Actions
- Apply Vendor Patches Immediately – Deploy the WSO2 and Adobe Commerce security updates released in response to CVE‑2026‑5430.
- Validate Remediation – Conduct post‑patch scans and file‑integrity checks to confirm the vulnerability is closed.
- Update Asset Inventories – Tag all WSO2 API Control Plane and Adobe Commerce instances for continuous compliance monitoring.
- Enable Log Monitoring – Configure alerts for anomalous file‑read requests and API‑plane errors.
- Document Evidence – Capture patch‑deployment logs and monitoring alerts as audit‑ready artifacts.
Source: The Hacker News – WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV