RaqibCTI
CVE

CVE-2026-5430

P2
WSO2 Multiple Products Path Traversal Vulnerability
WSO2 · Multiple Products
Date added (CISA)
2026-09-24
Remediation due
2026-09-27
Known ransomware use
Not indicated
Remediation priority
P2 — CISA due date imminent

Description

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

Source: NVD ↗ · CISA KEV Catalog ↗

CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability · RaqibCTI