Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Update: WSO2 API Manager vulnerability officially added to CISA’s KEV Catalog

Attackers are continuing to target CVE-2026-5430 months after it was first disclosed, despite repeated warnings.

• Fri, 25 Sep 2026 •
Update: WSO2 API Manager vulnerability officially added to CISA’s KEV Catalog

The United States Cybersecurity & Infrastructure Security Agency has added an authentication bypass vulnerability in the WSO2 API Manager to its Known Exploited Vulnerabilities Catalogue, making earlier warning signs of malicious activity targeting the platform official.

CVE-2026-5430 was added to the KEV list on September 24, alongside an incorrect authorisation vulnerability in Adobe Commerce and Magento (which the ACSC flagged as being actively exploited two weeks ago).

“These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise,” CISA said.

 
 

CVE-2026-5430 was initially disclosed in July, with malicious activity first detected in a honeypot run by cyber security firm WatchTowr.

“Our Attacker Eye global honeypot network captured forged JWT tokens arriving on September 13 with an ample number of administrator privileges already baked in and ready to ruin someone’s day,” Yordan Ganchev, principal threat intelligence specialist at the company, told Cyber Daily at the time.

Now, Ganchev has said the KEV addition proves his assertion that “this wasn't merely a theoretical vulnerability or a critical severity score on paper”.

Now, according to Ganchev, “It was exploitable, and attackers were already acting on it.”

“It’s worth reiterating that WSO2 isn’t a niche target. Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics,” Ganchev said overnight.

“Organisations in these sectors can't afford to wait for exploitation to be formally confirmed. By the time a vulnerability reaches the KEV catalog, attackers already have days, or, in this instance, weeks, to act.

“We’re well beyond simply identifying and scoring more vulnerabilities. Organisations need real-time visibility into attacker behaviour and the ability to rapidly reproduce vulnerabilities to validate their exposure and protect affected systems before public confirmation catches up.”

WSO2’s customers include ING, Qantas, Hilton, and the US Department of Justice.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: