Attackers are actively exploiting CVE-2026-5430, a CVSS 10 authentication-bypass vulnerability affecting WSO2 API Manager, API Control Plane, Traffic Manager, and Universal Gateway. The flaw results from improper JWT signature verification: vulnerable services accept tokens signed with unsupported algorithms, allowing attackers to forge JWTs with administrator privileges and bypass authentication. WatchTowr recorded exploitation attempts against its honeypots using forged administrative tokens.
Successful compromise can enable full administrative account takeover and expose API backend endpoints, registered application credentials, consumer keys, and other secrets. Attackers may also be able to intercept data in transit and access internal services reachable through affected API deployments. WSO2 released fixes in April 2026 through community pull requests and subscription update levels; organizations should apply the relevant updates immediately and investigate WSO2 environments for unauthorized administrator tokens or account activity.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
watchTowr's honeypot network recorded its first attempt to exploit CVE-2026-5430, involving forged JWTs containing administrator privileges. watchTowr reproduced the exploit by replaying the observed payload against the applicable WSO2 product.
The CVE record for the WSO2 authentication-bypass vulnerability was published in early August 2026.
WSO2 published a security advisory for critical JWT authentication-bypass vulnerability CVE-2026-5430 and made fixes available through community pull requests and support-subscription update levels.
WSO2 patched CVE-2026-5430, an authentication-bypass flaw affecting API Manager and related middleware products. The flaw allows forged JWTs signed with unsupported algorithms to be accepted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcethehackernews.com
Open sourcewatchtowr.com
Open sourcesecurity.docs.wso2.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.