WSO2 CVSS 10 API Flaw Exploited 12 Days Before KEV: Active Exploitation of CVE-2026-5430
This article reports on the critical JWT authentication bypass vulnerability CVE-2026-5430 affecting WSO2 API Manager (versions 4.1.0–4.6.0), API Control Plane, Traffic Manager, and Universal Gateway. The flaw carries a CVSS score of 10.0 in multi-tenant deployments (9.8 in single-tenant) and stems from improper JWT signature verification that allows attackers to forge tokens signed with unsupported algorithms and gain full administrative access. Although patches were available since April 2026, active exploitation was detected by watchTowr's honeypot network starting September 13, 2026, with CISA adding the vulnerability to its KEV catalog on September 24, 2026, mandating federal remediation by September 27. The article details the exploitation timeline, affected products, and defense recommendations including immediate patching and restricting access to management interfaces .
https://tech-insider.org/wso2-cvss-10-api-flaw-exploited-kev-2026/
Comments
Post a Comment