CVE-2026-5430 actively exploited: WSO2 Multiple Products Path Traversal Vulnerability
CISA added CVE-2026-5430, a path traversal in WSO2 Multiple Products, to its Known Exploited Vulnerabilities catalogue. It could allow for unrestricted file upload and lead to remote code execution. Federal agencies must remediate by September 27, 2026.
A path traversal flaw has been identified in the API Control Plane, API Manager, Traffic Manager and Universal Gateway components of WSO2 Multiple Products. The weakness could permit unrestricted file upload which may lead to remote code execution on affected systems. The issue is recorded as CVE‑2026‑5430 and has been placed on the CISA Known Exploited Vulnerabilities catalogue. All installations of the listed WSO2 components are potentially vulnerable, regardless of deployment model. Federal agencies that operate these products are specifically required to address the flaw. The extent of exploitation by ransomware actors remains uncertain, as no confirmed campaigns have been linked to the vulnerability. Stakeholders must apply the mitigations supplied by the vendor and follow the instructions in CISA’s BOD 26‑04 guidance for prioritizing security updates. Compliance with the “Forensics Triage Requirements” is also required. Agencies must complete remediation no later than 2026‑09‑27, or consider discontinuing use of the product where mitigation cannot be implemented.