Exploited Vulnerabilities Daily
🌐 English

← All new entries

CVE-2026-5430: WSO2 Multiple Products

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

Vendor
WSO2
Product
Multiple Products
Vulnerability
WSO2 Multiple Products Path Traversal Vulnerability
Date added
Sep 24, 2026
CISA due date (U.S. federal agencies)
Sep 27, 2026
Known ransomware campaign use
Unknown
Weakness (CWE)
CWE-347

References

This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.

Last updated: · Catalog version 2026.10.02