← All Advisories

CVE-2026-5430: WSO2 Multiple Products Path

Status: KEV  |  Advisory ID: CVE-2026-5430

Key Details

CVECVE-2026-5430
Affected productsWSO2 Multiple Products
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-347 (Improper Verification of Cryptographic Signature)
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-24.
Federal remediation deadline2026-09-27 (CISA KEV, Binding Operational Directive).

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
WSO2Multiple Products
SubsystemsGeneral OT
SectorsMultiple

What to Know

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

What to Do

Monitor WSO2's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-5430