Active Exploitation Alert: WSO2 API Manager / Gateway JWT Authentication Bypass — CVE-2026-5430 (WSO2-2026-5328) Added to CISA KEV

This security advisory warns of active exploitation of the critical vulnerability CVE-2026-5430 (WSO2-2026-5328), a JWT authentication bypass flaw caused by improper verification of cryptographic signature (CWE-347) in WSO2 API Manager, API Control Plane, Traffic Manager, and Universal Gateway products. CISA added the vulnerability to its KEV catalog on September 24, 2026, with in-the-wild exploitation confirmed since at least September 13, 2026. The flaw allows unauthenticated attackers to forge JWT tokens using unsupported algorithms to gain full administrative access.

https://www.rescana.com/post/wso2-api-manager-cve-2026-5430-kev

Comments

Popular posts from this blog

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know

Critical OpenSSH Flaws Enable MITM and DoS Attacks

MITRE ATT&CK v19 Redefines How Defenders Model Modern Threats