CISA Adds CVE-2026-5430 in WSO2 to Actively Exploited Vulnerabilities; Description Differs from Vendor
CISA added the CVE-2026-5430 vulnerability in WSO2 products to the KEV catalog. The vendor describes it as a JWT authentication bypass, while the CISA entry uses a different characterization of the flaw.

CVE-2026-5430 WSO2 was added on September 24, 2026, to the Known Exploited Vulnerabilities (KEV) catalog managed by the U.S. agency CISA. The inclusion means that CISA has evidence that the vulnerability is being exploited in real-world attacks. In the entry, it set a remediation deadline of September 27, 2026.
However, there is a significant discrepancy between the description in the KEV catalog and the vendor’s technical advisory. In the entry, CISA describes it as path traversal with the ability to upload files and remotely execute code. WSO2, by contrast, describes CVE-2026-5430 in its security advisory dated May 3, 2026, as a JWT authentication bypass involving a token signed with an unsupported algorithm.
CVE-2026-5430 WSO2 According to the Vendor
WSO2 states that the vulnerability concerns the processing of JSON Web Tokens. A token signed with an algorithm the product does not support may result in a JWT authentication bypass. According to the vendor, the impact ranges from unauthorized access to the possible takeover of an administrator account.
The affected products are API Control Plane, API Manager, Traffic Manager, and Universal Gateway in the specific versions listed in the security advisory. WSO2 has released fixes and set minimum update levels for supported deployments.
Publicly available materials do not make it possible to independently determine whether the description in KEV is an error or whether CISA recorded another method of exploiting the same identified vulnerability. CISA’s own public data also contains no technical details about the campaign or information about the attackers.
What Administrators Should Do
Organizations operating affected WSO2 products, especially those exposed to the internet, should immediately verify the versions in use and deploy fixes according to the WSO2 security advisory. For technical remediation, it is advisable to prioritize the vendor’s instructions, which specifically describe the flaw’s mechanism and the remediated product levels.
Inclusion in KEV also justifies checking whether there were signs of exploitation in the environment before the update. Although CISA confirms active exploitation, it has not published indicators of compromise or public technical details of the attacks.
What to Watch Next
- a correction or explanation of the difference between the CVE description in the KEV catalog and the WSO2 security advisory,
- any publication of indicators of compromise or technical details about the exploitation,
- confirmation that WSO2 installations are running the vendor-remediated update level.
Sources
- CISA Known Exploited Vulnerabilities Catalog – Confirms the inclusion of CVE-2026-5430 in KEV on September 24, 2026, the claim of active exploitation, and the remediation deadline.
- WSO2 Security Advisory WSO2-2026-5328/CVE-2026-5430 – Describes the actual nature of the flaw according to the vendor as a JWT authentication bypass, along with the affected products, impact, and available fixes.
- CISA KEV data mirror – The official mirror of CISA KEV catalog data, stating that it is updated following changes to the canonical catalog.
Verified and updated: September 25, 2026 06:23



