CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability

Summary

WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway are affected by a path traversal vulnerability. This flaw could enable unrestricted file uploads, potentially leading to remote code execution.

IFF Assessment

FOE

This vulnerability allows for unrestricted file uploads and remote code execution, posing a significant risk to systems and data.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 27, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in WSO2 products presents a critical risk, allowing for remote code execution. Defenders should prioritize applying vendor-provided mitigations and assess their exposure to this vulnerability, especially for internet-facing assets, adhering to CISA directives.

Read Full Story →