A CVSS 10 vulnerability in WSO2 is being actively exploited.
Attackers forge a JWT token. That's it. That's the exploit.
CVE-2026-5430 lets anyone bypass authentication on WSO2 API Manager, API Control Plane, Traffic Manager, and Universal Gateway.
Nearly 1,000 enterprises use WSO2 in banking, government, telecom, and logistics. Thousands more run it through open source deployments.
WatchTowr's honeypot caught the first real exploitation on September 13.
The attacker forged a JWT with an unsupported algorithm. WSO2 accepted it.
The result: access to every API backend endpoint. Every consumer key. Every secret. Every registered application.
WatchTowr called it "Lateral Movement-as-a-Service."
WSO2 patched this in April. The CVE record only appeared in August. Technical details still aren't public. WatchTowr reproduced the exploit from the patch alone.
"The only mystery here is what took everyone else so long."
If your enterprise runs WSO2 for API management or identity infrastructure, you are exposed right now. Not theoretically. Not next quarter. Now.
Audit your WSO2 deployments today. Check your versions. Apply the patch immediately. If you can't patch, restrict network access to management and gateway interfaces.
This is what happens when your API layer becomes the attack surface. One forged token. Full admin access. Complete lateral movement.
The attacker didn't need zero-days. They needed a JWT library and 10 minutes.
SOURCE: https://www.securityweek.com/enterprises-warned-of-attacks-exploiting-wso2-vulnerability/
VERIFIED: SecurityWeek, NVD/NIST CVE-2026-5430, WSO2 security advisory
SIGNAL: Your API gateway is the new perimeter. If it accepts forged tokens, every downstream system is compromised.
Your API gateway just became a turnstile. WSO2 CVSS 10 flaw is being exploited right now.
AI-Assisted Content — Produced with AI assistance and human editorial review.
Learn more
0 Comments