LIVE · cybersecurity feed
Live wire
vendor

Wso2

7 CVEs published in the last four months. Exploited flaws first.

Critical3
High4
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-543010criticalapi control planeThe JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or su30d ago
CVE-2026-17289.8criticalapi control planeTokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-30d ago
CVE-2025-150399.4criticalapi control planeThe Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all r30d ago
CVE-2026-42498.6highapi control planeThe throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without suffi61d ago
CVE-2025-104708.6highidentity serverThe Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting117d ago
CVE-2026-20538.3highapi managerThe WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validat71d ago
CVE-2025-109087.3highidentity serverDue to a lack of user account state validation during authentication, locked user accounts can be successfully aut117d ago

Filter the full tracker by Wso2