
Warning: #RCE vulnerabilities in #WSO2 API Manager and Identity Server. #CVE-2025-13590 (CVSS 9.1) allows arbitrary file upload in API Manager, while #CVE-2025-12107 (CVSS 8.4) enables template injection in Identity Server. #Patch #Patch #Patch More info: https://security.docs.wso2.com/en/latest/security-announcements/
Post summary
WSO2 issues a warning about two high‑severity CVEs affecting its API Manager and Identity Server, detailing the vulnerabilities and providing a patch via its security documentation.


