← All vendors
Vendor
WSO2
Security vulnerabilities in WSO2's enterprise identity and API management platforms, including WSO2 Identity Server, API Manager, and related integration products deployed across financial services and enterprise environments.
CVEs
[ CRITICAL ]CVSS 10.0EPSS 0.6%kev
WSO2 Multiple Products Path Traversal to RCE
WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway contain a path traversal flaw enabling unauthenticated file upload and remote code execution. CVSS 10.0. Actively exploited since September 13, 2026; added to CISA KEV September 24.
WSO2 / API Control Plane, API Manager, Traffic Manager, Universal Gateway
[ CRITICAL ]CVSS 9.8EPSS 100.0%kev
WSO2 Multiple Products Unrestrictive Upload of File Vulnerability
Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
WSO2 / Multiple Products
