SECURITY researchers have warned that attackers are exploiting CVE-2026-5430, a critical WSO2 vulnerability patched earlier this year. The flaw has a maximum CVSS score of 10 and affects WSO2 API Manager, API Control Plane, Traffic Manager and Universal Gateway. According to WSO2, JWT authentication can be bypassed when a token is signed with an unsupported algorithm, potentially granting unauthorised access, including administrative account compromise and full account takeover. WSO2’s platform is used by nearly 1,000 enterprise customers worldwide, with additional deployments through open-source users, OEMs and partners.
WatchTowr said its honeypot network recorded the first exploitation attempt on 13 September. The attacker used a forged JWT, which researchers said provided access to API backend endpoints, credentials, consumer keys and secrets for registered applications. Because the affected service can intercept API requests to internal systems, successful exploitation could also enable data theft and interaction with internal services.
WatchTowr said it observed one attacker targeting the wrong product, but confirmed that replaying the payload against the genuine WSO2 product worked. The company said it reproduced the vulnerability from WSO2’s patch, although technical details were not yet publicly available and the CVE record was only published in early August. Organisations using affected products should apply WSO2’s available fixes and investigate exposed systems for unauthorised access.