CISA Added WSO2 Vulnerability to Exploited Catalog

The cybersecurity agency identified a critical flaw allowing attackers to forge tokens with administrative access.

Updated on Sept. 25, 2026 in Cybersecurity

CISA Added WSO2 Vulnerability to Exploited Catalog

Live Poll

Do you trust that major technology providers act quickly enough to secure your data against hackers?

CISA has officially added the CVE-2026-5430 vulnerability to its Known Exploited Vulnerabilities catalog after discovering active exploitation in the wild. Malicious actors have used the flaw to generate forged JWT tokens, gaining unauthorized administrator privileges within affected systems.

Why it matters

The vulnerability poses significant security risks to the federal enterprise and thousands of organizations that rely on WSO2 technology. Adding this flaw to the catalog mandates that federal agencies address the issue to prevent further unauthorized access.

The flaw, tracked as CVE-2026-5430, allows attackers to bypass standard authentication by forging JWT tokens with administrator privileges. Nearly 1,000 WSO2 enterprise customers, including major entities like ING, Qantas, Hilton, and the US Department of Justice, utilize this technology.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is the primary federal body tasked with protecting the nation's critical infrastructure from cyber threats.

WSO2

WSO2 is a global software company that provides integration, API management, and identity solutions to large-scale enterprise customers.

WatchTowr

WatchTowr is a cybersecurity firm that specializes in continuous security testing and identifying emerging exploit patterns in real-world environments.

US Department of Justice

The United States Department of Justice is a federal executive department responsible for the enforcement of federal laws and the administration of justice.

The details

The exploit was detected by security firm WatchTowr on September 13, 2026, when they identified malicious activity targeting the vulnerability within a honeypot network. By leveraging administrator privileges through these tokens, threat actors can gain deep access to systems used for critical banking, logistics, and governmental operations.

Timeline

  1. July 2026: The CVE-2026-5430 vulnerability was initially disclosed.

  2. September 13, 2026: WatchTowr detected malicious activity involving forged JWT tokens.

  3. September 25, 2026: CISA formally added the vulnerability to the Known Exploited Vulnerabilities catalog.

The Tech Race

This vulnerability response follows the remediation timeline enforcement mandated by CISA's Binding Operational Directive 22-01. The rapid inclusion of this flaw into the catalog reflects the broader industry trend of tightening identity management security against sophisticated token forgery attacks.

Users and administrators of systems utilizing WSO2 software should immediately verify their security patches and monitor for unusual token-based authentication requests. Failure to remediate could allow attackers to bypass login security and gain full administrative control over sensitive enterprise data.

The takeaway

Security teams should prioritize patching systems that handle sensitive administrative tokens to prevent unauthorized access. Implementing robust token verification and monitoring remains the most effective defense against the current exploitation trend.

Further reading

For more information on national security measures, visit the Cybersecurity section.

Source note: This article includes information reported by Cyberdaily.

Live Poll

Do you trust that major technology providers act quickly enough to secure your data against hackers?