HIGHVulnerability
Verified
Global

CISA KEV: WSO2 Multiple Products — WSO2 Multiple Products Path Traversal Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

Analysis

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-24. Remediation due: 2026-09-27.

Indicators of Compromise (1)

CVE (1)
CVE-2026-5430
Source Attribution

Originally published by CISA KEV on Sep 24, 2026. Verified by: CISA.

Related Threats