Topic

WSO2

Latest WSO2 coverage — 1 article.

CVE-2026-5430: WSO2's JWT Algorithm Bypass Is Being Exploited for Lateral Movement
CISA KEV · CVE · Active Exploitation · Security Alert · WSO2

CVE-2026-5430: WSO2's JWT Algorithm Bypass Is Being Exploited for Lateral Movement

WatchTowr's honeypot network caught active exploitation of a WSO2 JWT algorithm bypass, with forged tokens granting full access to every backend API a compromised gateway proxies. CISA added it to KEV; federal agencies must patch by September 27.

4 min read