What happened
CISA added CVE-2026-5430 to the KEV catalog on 24 Sept 2026: WSO2 API Control Plane / API Manager / Traffic Manager / Universal Gateway path traversal yielding unrestricted file upload and RCE, with confirmed in-the-wild exploitation.
Why it matters
WSO2 is the API gateway for many enterprise AI workloads; a pre-auth RCE at the API layer can compromise the gateway that also brokers access to AI endpoints - treat as immediate patch priority even though not AI-specific.
Attack vector
Path traversal allowing unrestricted file upload leading to remote code execution in WSO2 API management products; CISA KEV confirms exploitation in the wild (added 24 Sept 2026, federal due date 27 Sept 2026).
Affected systems
WSO2 API Control Plane, API Manager, Traffic Manager, Universal Gateway
Mitigation
Apply WSO2-2026-5328 mitigations per vendor security advisory; follow BOD 26-04 guidance (federal due 2026-09-27).