CISA Flags a WSO2 Flaw Already Under Active Exploitation
Want more insights like this?
CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog on September 24, with a September 27 federal deadline that has now passed. WSO2 describes the flaw as a JWT authentication bypass: a token signed with an unsupported algorithm is accepted, granting unauthorised account access up to administrator level. It is rated CVSS 10.0, or 9.8 on single-tenant deployments, and needs no credentials.
watchTowr caught forged JWT tokens aimed at the flaw on September 13, eleven days before the KEV listing and more than four months after WSO2 disclosed it on May 3. Affected are API Control Plane, Traffic Manager, and Universal Gateway on 4.5.0 and 4.6.0, plus API Manager from 4.1.0 through 4.6.0. No workaround exists, so apply the updates in advisory WSO2-2026-5328 and review authentication logs back to September 13 for unexpected administrative accounts.
Source: Cybersecurity News