CISA added CVE-2026-5430 to the exploited catalogue on Wednesday with a three day deadline.
The record contradicts itself.
📄 Its name: "WSO2 Multiple Products Path Traversal Vulnerability". Its description: a path traversal allowing unrestricted file upload and remote code execution.
Its CWE field, in the same record: CWE-347, improper verification of a cryptographic signature.
The two pages the record links to, WSO2's own advisory and the NVD entry, both describe a third thing that matches the CWE and not the name: JWT authentication is bypassed when a token is signed with an algorithm the server does not support. Neither source contains the words path traversal. Neither mentions file upload.
🔎 This matters because the name is what travels.
Triage from it and you go hunting for dot dot slash sequences in web server logs, files written outside their directory, web shells in upload folders, traversal coverage in your WAF. You will find nothing. The real flaw leaves none of those traces: it produces a correctly formed authenticated request, and potentially an administrative session.
The machine readable field was right. The two fields written by hand were wrong. Guess which one your vulnerability platform puts on the ticket.
🧾 The rest of the record, for anyone triaging it now.
CVSS 10.0, assigned by WSO2 as CNA, reduced by WSO2 itself to 9.8 for single tenant deployments. NVD has published no score of its own. Affected: API Control Plane, Traffic Manager and Universal Gateway 4.5.0 and 4.6.0, API Manager 4.1.0 through 4.6.0. Credited to the Hacktron Team.
⏳ The vendor advisory is dated 3 May. NVD published on 6 August. The catalogue entry landed 144 days after the advisory, with a deadline of three days, under BOD 26-04, flagged for forensic triage.
⚖️ The control in the experiment is the other entry added the same day. Adobe Commerce CVE-2026-71362: KEV name, CWE-863 and Adobe's own bulletin all agree. Same team, same release, one right and one wrong.
📌 Change the habit. Read the cwes field and the linked vendor advisory before the vulnerabilityName. One of those is written by a machine.
https://www.pk-sharma.com/briefing/kev-entry-describes-the-wrong-flaw
#ThreatIntel #VulnerabilityManagement #KEV #CISA #WSO2 #Adobe #APISecurity #JWT #PatchManagement #InfoSec #CyberSecurity #BlueTeam #SOC #CISO