CVE-2026-5430Active Exploitation(wso2 / api_control_plane)

HIGHCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 35 mentions and remains active

Immediate actions

  • Patch wso2 api_control_plane systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

7.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-27. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-347

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • api_control_plane
  • api_manager
  • traffic_manager
  • universal_gateway

Threat summary

  • Active exploitation appears in 25 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 96 mentions across 15 observed days

What's happening

  • Active exploitation reported across 25 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 33 signals
  • Disclosure: 7 classified signals
  • Peaked 3d ago at 35 mentions (2026-09-25); latest day: 2
  • 96 total mentions across 15 days

Affected systems

Vendors
Products
api_control_planeapi_managertraffic_manageruniversal_gateway

Deep dive

Activity timeline96 mentions / 15d
09182635Mentions · 2026-06-30: 1Mentions · 2026-08-06: 2Mentions · 2026-08-07: 4Mentions · 2026-08-10: 1Mentions · 2026-09-16: 23Mentions · 2026-09-17: 4Mentions · 2026-09-18: 3Mentions · 2026-09-19: 1Mentions · 2026-09-21: 1Mentions · 2026-09-23: 1Mentions · 2026-09-24: 3Mentions · 2026-09-25: 35Mentions · 2026-09-26: 10Mentions · 2026-09-27: 5Mentions · 2026-09-28: 2PoC Mentioned / Linked · 2026-08-07: 1PoC Mentioned / Linked · 2026-09-16: 2PoC Mentioned / Linked · 2026-09-17: 1Active Exploitation · 2026-09-16: 19Active Exploitation · 2026-09-17: 1Active Exploitation · 2026-09-18: 3Active Exploitation · 2026-09-19: 1Active Exploitation · 2026-09-25: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-08-07: 2Patch / Workaround · 2026-08-10: 1Patch / Workaround · 2026-09-16: 9Patch / Workaround · 2026-09-19: 1Patch / Workaround · 2026-09-25: 1Technical Details · 2026-06-30: 1Technical Details · 2026-08-06: 2Technical Details · 2026-08-07: 3Technical Details · 2026-08-10: 1Technical Details · 2026-09-16: 19Technical Details · 2026-09-17: 2Technical Details · 2026-09-18: 3Technical Details · 2026-09-19: 1Technical Details · 2026-09-25: 106-3008-0608-0708-1009-1609-1709-1809-1909-2109-2309-2409-2509-2609-2709-28
Signal classification5 categories
Active Exploitation
2562.5%
Disclosure
717.5%
Patch
512.5%
General
25.0%
PoC
12.5%
Referenced assets78 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-301
Patch1
2026-08-062
Disclosure2
2026-08-074
Disclosure1General1Patch2
2026-08-101
Patch1
2026-09-1623
Active Exploitation19Disclosure3Patch1
2026-09-174
Active Exploitation1Disclosure1General1PoC1
2026-09-183
Active Exploitation3
2026-09-191
Active Exploitation1
2026-09-2535
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ Forged admin JWTs are being used in WSO2 API Manager exploitation attempts. CVE-2026-5430 lets unsupported JWT algorithms bypass authentication and can lead to account takeover. Fixes are available. Read: https://thehackernews.com/2026/09/active-exploitation-attempts-target.html

    Post summary

    The text reports active exploitation attempts targeting WSO2 API Manager via CVE-2026-5430, where forged admin JWTs exploit unsupported algorithms to bypass authentication and achieve account takeover, while noting that fixes exist.

    7211753936.7K
    2.4M followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🔴 WSO2 API Manager'da JWT doğrulama mekanizmasındaki hata, desteklenmeyen algoritmayla oluşturulan token'ların yanlış işlenmesine ve unauthenticated authentication bypass oluşmasına neden oluyor. CVE-2026-5430 - CVSS 10.0 olarak takip edilen bu açık için @abraxas_null tarafından PoC yayınlandı. PoC, sahte HS256 JWT ile /api/am/admin/v4/tenant-config endpoint'ine kimlik doğrulaması olmadan erişimi gösteriyor. Etkilenen: API Manager, API Control Plane, Traffic Manager, Universal Gateway. WSO2 API Manager: 4.5.0 Update 57+ yama PoC: https://github.com/abraxas/CVE-2026-5430

    110035182.1K
    2.4K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CISA KEV — WSO2 MULTIPLE PRODUCTS CVE-2026-5430 (CRITICAL AUTH BYPASS / ACCOUNT TAKEOVER) CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities (KEV) Catalog on September 24, 2026, based on evidence of active exploitation. Products (vendor advisory WSO2-2026-5328): • WSO2 API Control Plane 4.6.0, 4.5.0 • WSO2 API Manager 4.6.0–4.1.0 • WSO2 Traffic Manager 4.6.0, 4.5.0 • WSO2 Universal Gateway 4.6.0, 4.5.0 Vendor severity: Critical — CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H); adjusted to 9.8 for single-tenant deployments Vendor overview: JWT authentication can be bypassed when a token is signed using an unsupported algorithm, enabling unauthorized access and potential admin account takeover CWE (KEV): CWE-347 (Improper Verification of Cryptographic Signature) Federal due date: September 27, 2026 (BOD 26-04); forensic triage: Yes ⚠️ Analyst Note: This is an official CISA KEV addition (catalogVersion 2026.09.24; count 1723; dateReleased 2026-09-24T19:00:55Z) plus WSO2’s official security advisory. Prefer those primaries over secondary media. CISA’s KEV shortDescription labels this a “path traversal” that could enable unrestricted file upload / RCE, while the linked vendor advisory WSO2-2026-5328 and CWE-347 describe JWT authentication bypass / account takeover. Post from the vendor technical description; note CISA’s active-exploitation signal and due date. CISA has not published a detailed exploitation-campaign narrative in the KEV entry; treat “known exploited” as the authoritative urgency signal and apply vendor fixes / BOD 26-04 guidance. Official vendor advisory: https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/ CISA alert (two-KEV add): https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog CISA KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog #DDW #DarkWeb #CISA #KEV #WSO2 #CVE20265430 #APISecurity #ThreatIntelligence #CyberSecurity

    1403187.0K
    205.2K followersView on X
  • CISA Cyber@CISACyber

    🛡️We added WSO2 path traversal vulnerability CVE-2026-5430 & Adobe Commerce & Magento incorrect authorization vulnerability CVE-2026-71362 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/gCOou6c0gX

    7602808.6K
    302.8K followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 WSO2 has patched four critical account takeover vulnerabilities, including CVE-2026-5430 (CVSS 10.0). The flaw allows authentication bypass via JWT, potentially leading to full account compromise. Users are urged to update immediately. #WSO2 #JWT #CVE #CyberSecurity #AccountTakeover #Infosec

    Post summary

    WSO2 has released patches for critical JWT authentication bypass vulnerabilities and urges users to update immediately to prevent possible account takeover.

    0402191.8K
    1.5K followersView on X
  • TRSiber | Siber Bilgi Ağı@trsiberyazilim

    💢WSO2 API Manager'da CVSS 10 puanlı JWT açığı (CVE-2026-5430) saldırılarda aktif olarak istismar ediliyor. Saldırganlar sahte token üreterek imza anahtarı olmadan yönetici erişimi elde edebiliyor. CISA açığı istismar edilen açıklar kataloğuna ekledi ve federal kurumlara yama için yalnızca üç gün süre verdi. 4.1.0–4.6.0 sürümlerini kullananların güncellemeleri hemen uygulaması, JWT kayıtlarını ve beklenmedik yönetici hesaplarını incelemesi öneriliyor. Detaylar 👇 https://www.trsiber.net/siber-dunya-haberleri/167-wso2-api-manager-da-cvss-10-puanli-jwt-acigi-saldirilarda-cve-2026-5430-ile-sahte-token-yonetici-erisimi-sagliyor-cisa-uc-gun-sure-verdi #SiberGüvenlik #WSO2 #CVE20265430 #JWT #CISA #APIGüvenliği #SonDakika #Gündem

    010320228
    358 followersView on X
  • abraxas@abraxas_null

    I got scooped on the disclosure, so here's a free exploit :) WSO2 API Manager - Unauthorized Account Takeover (Critical 10). https://github.com/abraxas/CVE-2026-5430

    06195466
    143 followersView on X
  • ExploitGrid@exploitgrid

    🔓 A JWT algorithm mismatch can bypass WSO2 authentication. CVE-2026-5430 affects multiple WSO2 products and can lead to account takeover. CVSS 10.0 | KEV | Public exploit ExploitGrid: 95/100 Critical 🔎 https://exploitgrid.net/vulnerabilities/CVE-2026-5430

    00062186
    127 followersView on X
  • ExploitGrid@exploitgrid

    🔴 CVE-2026-5430; WSO2 API Manager | CVSS 10.0 Attackers are forging JWT tokens with unsupported algorithms, and WSO2 just accepts them. Result? Full admin account takeover. No credentials. No brute force. Just a crafted token.

    1105059
    129 followersView on X
  • ExploitGrid@exploitgrid

    🚨 CISA KEV | CRITICAL CVE-2026-5430 affects multiple WSO2 products with a CVSS 10.0 JWT authentication bypass. ⚠️ Known Exploited — added to CISA KEV on Sep 24 🔓 Authentication bypass 🎯 Potential admin account takeover 📌 CWE-347

    2102167
    128 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 استغلال نشط لمحاولات استهداف WSO2 API Manager لتجاوز JWT باستخدام رموز مدير مزيفة 🛡️ الفئة: ثغرة 📝 الملخص: قامت جهات خبيثة باستغلال ثغرة حرجة في WSO2 API Manager في البيئة الحية، وفقًا لتقارير watchTowr. الثغرة (CVE-2026-5430) تتسبب في عدم التحقق الصحيح من توقيع JWT، ما يتيح هجوم استيلاء على الحساب عبر رموز مدير مزيفة. حصلت على تصنيف CVSS 9.8/10، وتستهدف أنظمة إدارة واجهات برمجة التطبيقات التي تعتمد على JWT. تم اكتشاف الثغرة وإبلاغها من قبل فريق Hacktron، ويوصى بتطبيق التصحيح الفوري وتفعيل مراقبة الأنشطة غير الاعتيادية. 🗓️ تاريخ النشر: 16/09/2026 🔗 للمزيد: https://thehackernews.com/2026/09/active-exploitation-attempts-target.html

    Post summary

    The post confirms active exploitation of CVE-2026-5430 in the wild, a critical JWT signature bypass vulnerability in WSO2 API Manager with CVSS 9.8/10. It also recommends immediate patching, but active exploitation is the primary focus.

    00060741
    435 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    WSO2 patched four critical account takeover flaws, including CVE-2026-5430 at CVSS 10 via JWT auth bypass. Details and fixes inside. #WSO2 #AccountTakeover #CVE #APIsecurity #CyberSecurity http://securityonline.info/wso2-account-takeover-flaws/

    Post summary

    WSO2 released patches for four critical account takeover flaws, including CVE‑2026‑5430 rated CVSS 10 with a JWT auth bypass vulnerability; the post links to detailed fix information.

    11022612
    13.0K followersView on X
  • BrainLabVisions@BrainLabVisions

    1. CVE-2026-5430 With WEBOUNCER in front: -The upload/path-traversal request would hit only the digital twin. -The twin has no real file system access to the production WSO2 servers and no ability to write executable content into the real environment. ...

    1003037
    63 followersView on X
  • YourDailyCVE@YourDailyCVE

    🚨 CVE-2026-5430 — WSO2 API Manager / Gateway, unauth takeover. CVSS 10.0. KEV Sep 24. Who should care: anyone running WSO2 API Manager (4.1–4.6), API Control Plane, Traffic Manager, or Universal Gateway (4.5–4.6) below the WSO2-2026-5328 updates. This box sits in front of your APIs. Own it and you own the traffic behind it. What broke: login on these products trusted a token it should not have. No account needed. Attacker gets in as an admin and can run code on the host. CISA lists the same CVE as path traversal → file upload → RCE. Same advisory. Same products. Status: WSO2 shipped the fix in spring. CVE dropped in August. Exploitation against honeypots from 13 Sep. CISA KEV 24 Sep. Due 27 Sep. Credit: http://hacktron.ai. Fix today: apply WSO2-2026-5328. Floor versions include Control Plane 4.5.0.58 / 4.6.0.22 and API Manager updates through 4.1.0.257 (and the matching 4.2–4.6 takes). Check the advisory table for your exact train. Subscription = WSO2 Updates. OSS = the carbon-apimgt / product-apim patches named in that note.Can't patch: take the admin and gateway UIs off the internet. Allowlist who can hit token endpoints. That is delay. Do this now: if you run WSO2 APIM or the gateway, apply 5328 this weekend and reply “patched.” Source: WSO2-2026-5328 / CISA KEV / watchTowr / The Hacker News #WSO2 #API

    10020111
    32 followersView on X
  • CyberSignal | Cybersecurity & AI News@XQOPTRX

    🚨CISA ADDS WSO2 AND ADOBE COMMERCE FLAWS TO KEV CISA has added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence of exploitation in real attacks. 🔴 CVE-2026-5430 CVSS: 9.8 Affects multiple WSO2 products including API Manager and Universal Gateway. The path-traversal flaw can enable unrestricted file upload and ultimately remote code execution. 🔴 CVE-2026-71362 CVSS: 9.1 Affects Adobe Commerce and Magento. Attackers can potentially abuse the authorization flaw to gain elevated access to sensitive resources without user interaction. CISA has instructed U.S. federal civilian agencies to remediate both vulnerabilities by September 27, 2026. 🛡️ Defender priority: Internet-facing WSO2 and Adobe Commerce environments should be treated as urgent remediation targets. Sources: The Hacker News · SecurityAffairs.

    1101052
    231 followersView on X
  • MadeItHappen@MadeItHappenX

    Kids, CISA put WSO2 CVE-2026-5430 on KEV. Path traversal to upload to RCE on API Manager and Gateway. watchTowr caught forged JWT traffic Sep 13. Catalog day is not day zero, mmkay. https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html https://t.co/nPgSmljd8C

    10020231
    259 followersView on X
  • P.K. Sharma@_pksharma

    CISA added CVE-2026-5430 to the exploited catalogue on Wednesday with a three day deadline. The record contradicts itself. 📄 Its name: "WSO2 Multiple Products Path Traversal Vulnerability". Its description: a path traversal allowing unrestricted file upload and remote code execution. Its CWE field, in the same record: CWE-347, improper verification of a cryptographic signature. The two pages the record links to, WSO2's own advisory and the NVD entry, both describe a third thing that matches the CWE and not the name: JWT authentication is bypassed when a token is signed with an algorithm the server does not support. Neither source contains the words path traversal. Neither mentions file upload. 🔎 This matters because the name is what travels. Triage from it and you go hunting for dot dot slash sequences in web server logs, files written outside their directory, web shells in upload folders, traversal coverage in your WAF. You will find nothing. The real flaw leaves none of those traces: it produces a correctly formed authenticated request, and potentially an administrative session. The machine readable field was right. The two fields written by hand were wrong. Guess which one your vulnerability platform puts on the ticket. 🧾 The rest of the record, for anyone triaging it now. CVSS 10.0, assigned by WSO2 as CNA, reduced by WSO2 itself to 9.8 for single tenant deployments. NVD has published no score of its own. Affected: API Control Plane, Traffic Manager and Universal Gateway 4.5.0 and 4.6.0, API Manager 4.1.0 through 4.6.0. Credited to the Hacktron Team. ⏳ The vendor advisory is dated 3 May. NVD published on 6 August. The catalogue entry landed 144 days after the advisory, with a deadline of three days, under BOD 26-04, flagged for forensic triage. ⚖️ The control in the experiment is the other entry added the same day. Adobe Commerce CVE-2026-71362: KEV name, CWE-863 and Adobe's own bulletin all agree. Same team, same release, one right and one wrong. 📌 Change the habit. Read the cwes field and the linked vendor advisory before the vulnerabilityName. One of those is written by a machine. https://www.pk-sharma.com/briefing/kev-entry-describes-the-wrong-flaw #ThreatIntel #VulnerabilityManagement #KEV #CISA #WSO2 #Adobe #APISecurity #JWT #PatchManagement #InfoSec #CyberSecurity #BlueTeam #SOC #CISO

    2001068
    189 followersView on X
  • VulnTracker@vuln_tracker

    A perfect CVSS 10.0 in WSO2 is now actively exploited and on CISA's KEV list. CVE-2026-5430 lets an attacker craft a JWT signed with an unsupported algorithm that gets validated anyway, bypassing authentication with zero credentials. It affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway, and can lead to full administrative account takeover. Remediate by Sep 27, 2026. Details: http://vulntracker.io/cves/CVE-2026-5430 #WSO2 #CVE #InfoSec #CyberSecurity

    00021171
    781 followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    WSO2 patched seven flaws across API Manager and gateways, led by a CVSS 10 JWT auth bypass (CVE-2026-5430). Update WSO2 API Manager now. #WSO2 #APISecurity #CVE #AuthBypass #Cybersecurity #Infosec https://securityonline.info/wso2-api-manager-vulnerabilities https://t.co/SWv564o6pX

    Post summary

    WSO2 has released patches for seven vulnerabilities, including a critical JWT auth bypass (CVE-2026-5430). Users are advised to update their WSO2 API Manager to mitigate the risks.

    01020618
    12.9K followersView on X
  • dbugs@ptdbugs

    A PoC/exploit has been discovered for vulnerability CVE-2026-5430 PT ID: PT-2026-53824 Vendor: WSO2 Product: WSO2 Universal Gateway Description: The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary. References: • https://dbu.gs/vulnerability/PT-2026-53824 • https://github.com/abraxas/cve-2026-5430

    00020159
    3.6K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appwso2api_control_plane---
Appwso2api_manager---
Appwso2traffic_manager---
Appwso2universal_gateway---

Explore more