Exploited in the wild API Manager auth-bypass Traffic Manager WSO2 info-disclosure
Enterprises Warned of Attacks Exploiting WSO2 Vulnerability
CVE Tools coverage
Attackers are exploiting CVE-2026-5430, a CVSS 10 WSO2 vulnerability patched in April, to bypass JWT authentication and gain unauthorized access. The flaw affects API Manager, Traffic Manager, Universal Gateway, and API Control Plane, and may enable administrative account takeover, access to API credentials and secrets, and interception of sensitive data. Organizations using affected WSO2 products should apply the available patch promptly.