ZeroDayAlert

CVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

WSO2 Multiple Products Added to KEV 2026-09-24 Federal due 2026-09-27 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

This vulnerability affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway. The record does not specify which versions are vulnerable, the nature of the path traversal mechanism, or whether all deployment modes (cloud, on-premises, hybrid) are equally exposed. If you run any of these WSO2 products, you should treat this as potentially applicable to your environment.

How to check whether this touches you

  • Search your infrastructure inventory and configuration management database for instances of WSO2 API Control Plane, API Manager, Traffic Manager, or Universal Gateway.
  • Establish whether any of these services are accessible from untrusted networks—primarily the internet, but also from network segments you do not fully control.
  • Obtain the exact version number of each running instance from the product's administrative interface or logs; version alone does not confirm vulnerability status, but it is the starting point for vendor guidance matching.
  • Check whether your instances are cloud-hosted via WSO2 (where the vendor may have already patched) or self-managed.

What to do

  1. Immediately obtain vendor mitigation or patching instructions from WSO2 for your specific product and version; do not assume all versions or deployment modes have the same fix.
  2. If patching is not yet available or will be delayed, restrict network access to affected services—remove public DNS records, firewall off inbound routes, or move services behind additional authentication layers until remediation is in place.
  3. Enable and review all file upload and execution logs on affected systems; path traversal attempts often leave traces in access logs, though they may be subtle.
  4. If your instance is cloud-hosted, contact WSO2 support to confirm patching status and timeline on your account.
  5. Escalate to your security team and compliance function if the service is internet-facing, handles sensitive data, or supports critical workflows; the vulnerability chain includes remote code execution.

If you find you were exposed

Examine web server and application logs covering at least the last three months for suspicious file paths, traversal sequences (patterns with ../ or encoded variants), or unexpected file uploads. Successful exploitation typically leaves evidence of file writes or process execution shortly after the malicious request. Retention of these logs is your primary tool; without them, detection is severely limited. Engage your forensics team and WSO2 support to review any suspicious activity and confirm whether code execution occurred.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-5430 is being exploited. It cannot tell you whether Multiple Products is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →