BREAKING NEWSBREAKING: ASOS Confirms Customer Data May Have Been Accessed in Cyber Incident
Monitoring active · Brevard County, Florida

A3E Cyber Blog

BREAKING: CISA Confirms Active Exploitation of Critical WSO2 Authentication Bypass

September 25, 2026: The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-5430, a critical vulnerability affecting multiple WSO2 API management products, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.

What is CVE-2026-5430?

WSO2 describes CVE-2026-5430 as an authentication bypass in JWT handling. A token signed with an unsupported algorithm may be improperly accepted, allowing an unauthenticated attacker to gain unauthorized access.

WSO2 rates the vulnerability Critical with a CVSS score of 10.0 in affected multi-tenant scenarios and 9.8 in single-tenant deployments. Successful exploitation may compromise administrative accounts and lead to full account takeover.

Which WSO2 products are affected?

The vendor advisory lists WSO2 API Control Plane 4.5.0 and 4.6.0; API Manager 4.1.0 through 4.6.0; Traffic Manager 4.5.0 and 4.6.0; and Universal Gateway 4.5.0 and 4.6.0 as affected.

Active exploitation confirmed

CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog on September 24 after evidence that attackers are exploiting the vulnerability in real-world activity. Security reporting also cites honeypot observations of forged JWT tokens targeting the weakness before the KEV addition.

The KEV listing establishes that exploitation is occurring, but publicly available information does not establish that every exposed WSO2 system has been compromised. CISA has not identified this vulnerability as known to be used in ransomware campaigns.

What defenders should do now

Apply WSO2 fixes

Administrators should follow WSO2’s security advisory and apply the relevant product fix or supported update level immediately. Community users who cannot apply the fix should migrate to an unaffected version as directed by WSO2.

Identify exposed systems

Inventory affected WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway deployments, with particular attention to systems reachable from the internet.

Review for possible compromise

Security teams should review authentication and application logs for unexpected JWT activity, unauthorized administrative access, newly created or modified accounts, unusual configuration changes and suspicious outbound connections. Organizations should preserve relevant logs before remediation when compromise is suspected.

Rotate credentials when warranted

If investigation indicates unauthorized administrative access, rotate affected credentials, tokens and secrets and investigate connected systems that could have been reached from the WSO2 environment.

Why this matters

WSO2 API infrastructure can sit in front of sensitive business applications and services. An authentication bypass affecting administrative access can therefore create risk beyond the API management server itself. Organizations using affected versions should treat the KEV addition as an urgent remediation signal.

A3E Cyber will continue monitoring CVE-2026-5430 for additional technical details, indicators of compromise and confirmed attack activity.

Next step

Want this checked on your own systems?

The assessment is free and the summary is yours to keep either way.

Leave a comment

Your email address will not be published. Required fields are marked *

Call now Book an assessment