Active Exploitation Alert: WSO2 API Manager / Gateway JWT Authentication Bypass — CVE-2026-5430 (WSO2-2026-5328) Added to CISA KEV
This security advisory warns of active exploitation of the critical vulnerability CVE-2026-5430 (WSO2-2026-5328), a JWT authentication bypass flaw caused by improper verification of cryptographic signature (CWE-347) in WSO2 API Manager, API Control Plane, Traffic Manager, and Universal Gateway products. CISA added the vulnerability to its KEV catalog on September 24, 2026, with in-the-wild exploitation confirmed since at least September 13, 2026. The flaw allows unauthenticated attackers to forge JWT tokens using unsupported algorithms to gain full administrative access.
https://www.rescana.com/post/wso2-api-manager-cve-2026-5430-kev
Comments
Post a Comment