September 25, 2026: The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-5430, a critical vulnerability affecting multiple WSO2 API management products, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.
What is CVE-2026-5430?
WSO2 describes CVE-2026-5430 as an authentication bypass in JWT handling. A token signed with an unsupported algorithm may be improperly accepted, allowing an unauthenticated attacker to gain unauthorized access.
WSO2 rates the vulnerability Critical with a CVSS score of 10.0 in affected multi-tenant scenarios and 9.8 in single-tenant deployments. Successful exploitation may compromise administrative accounts and lead to full account takeover.
Which WSO2 products are affected?
The vendor advisory lists WSO2 API Control Plane 4.5.0 and 4.6.0; API Manager 4.1.0 through 4.6.0; Traffic Manager 4.5.0 and 4.6.0; and Universal Gateway 4.5.0 and 4.6.0 as affected.
Active exploitation confirmed
CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog on September 24 after evidence that attackers are exploiting the vulnerability in real-world activity. Security reporting also cites honeypot observations of forged JWT tokens targeting the weakness before the KEV addition.
The KEV listing establishes that exploitation is occurring, but publicly available information does not establish that every exposed WSO2 system has been compromised. CISA has not identified this vulnerability as known to be used in ransomware campaigns.
What defenders should do now
Apply WSO2 fixes
Administrators should follow WSO2’s security advisory and apply the relevant product fix or supported update level immediately. Community users who cannot apply the fix should migrate to an unaffected version as directed by WSO2.
Identify exposed systems
Inventory affected WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway deployments, with particular attention to systems reachable from the internet.
Review for possible compromise
Security teams should review authentication and application logs for unexpected JWT activity, unauthorized administrative access, newly created or modified accounts, unusual configuration changes and suspicious outbound connections. Organizations should preserve relevant logs before remediation when compromise is suspected.
Rotate credentials when warranted
If investigation indicates unauthorized administrative access, rotate affected credentials, tokens and secrets and investigate connected systems that could have been reached from the WSO2 environment.
Why this matters
WSO2 API infrastructure can sit in front of sensitive business applications and services. An authentication bypass affecting administrative access can therefore create risk beyond the API management server itself. Organizations using affected versions should treat the KEV addition as an urgent remediation signal.
A3E Cyber will continue monitoring CVE-2026-5430 for additional technical details, indicators of compromise and confirmed attack activity.