CVE-2026-5430: WSO2 Multiple Products Path
Status: KEV
| Advisory ID: CVE-2026-5430
Key Details
| CVE | CVE-2026-5430 |
| Affected products | WSO2 Multiple Products |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-347 (Improper Verification of Cryptographic Signature) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-24. |
| Federal remediation deadline | 2026-09-27 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
What to Do
Monitor WSO2's web page for any future patch releases.
References