CISA put WSO2 on KEV. The catalog row says path traversal. WSO2 says JWT.
CVE-2026-5430 is CWE-347, not a file-upload RCE. Catalog 2026.09.24, due 27 September. watchTowr had admin JWTs on 13 September.
Bottom line up front
CONFIRMED CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog on 24 September 2026. Catalog version 2026.09.24 (released 24 September 19:00 UTC, count 1723). Two new rows since [yesterday’s WordPress Daily Top](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/). Federal due date is 27 September 2026. Ransomware-campaign use is Unknown. Forensic triage is Yes. CISA-ADP SSVC on the NVD record, stamped 24 September 00:00 UTC: exploitation active, automatable yes, technical impact total.
The product set is WSO2 API Manager, API Control Plane, Traffic Manager, and Universal Gateway. The vendor bug is not a path traversal. WSO2-2026-5328 (published 3 May 2026) and the WSO2 CNA record are CWE-347: JWT authentication accepts a token signed with an unsupported algorithm, then treats it as valid. Vendor score is 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, adjusted to 9.8 with S:U on single-tenant deployments. Unauthenticated account takeover, including administrative accounts.
Do not collapse three facts.
- CISA’s KEV title does not match the vendor primitive. The JSON row is named “WSO2 Multiple Products Path Traversal Vulnerability.” The short description talks about unrestricted file upload and remote code execution. The same row lists CWE-347. WSO2’s advisory, the CVE.org description, and NVD all describe JWT algorithm mismatch. Hunt and ticket against the vendor bug. A scanner looking for a Magento-style file write will miss this.
- The patch is months old. The catalog row is not. WSO2 says support-subscription holders apply a listed update level. SecurityWeek restated that WSO2 patched in April; the public advisory is 3 May; the CVE record is 6 August. watchTowr’s honeypots logged forged JWTs with administrator privileges on 13 September. CISA’s add is 24 September. A box that was “current in March” is not this close.
- Honeypot traffic is not a victim list. watchTowr (Yordan Ganchev) reported a single attacker hitting the wrong product; replaying the payload on API Manager worked. CISA’s KEV criterion is evidence of exploitation, not a named breach. Named victims remain UNKNOWN.
This is not a re-run of [yesterday’s WordPress Core include](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/). Different vendor, different plane, different clock. [F5 APM CVE-2026-94127](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/) is due today.
| Fact | Record |
|---|---|
| CVE | CVE-2026-5430 |
| Product | WSO2 API Manager 4.1.0–4.6.0; API Control Plane 4.5.0/4.6.0; Traffic Manager 4.5.0/4.6.0; Universal Gateway 4.5.0/4.6.0 |
| Vendor advisory | WSO2-2026-5328 (3 May 2026) |
| Vendor score | CVSS 3.1 10.0 (9.8 single-tenant) |
| CWE (vendor / NVD / KEV row) | CWE-347 |
| KEV catalog | 2026.09.24, count 1723 |
| Added / due | 24 September / 27 September 2026 |
| Exploitation | CONFIRMED as KEV; watchTowr honeypot JWTs 13 Sep |
| Ransomware use | Unknown |
| Named CISA actor | None |
| OT / process impact | None claimed |
What happened
CISA’s 24 September alert names two CVEs. The JSON freeze we retrieved is catalog 2026.09.24, dateReleased 2026-09-24T19:00:55Z, count 1723 (yesterday’s WordPress Daily Top froze 2026.09.23 at 1721). The 5430 row: vendor WSO2, product “Multiple Products,” due 27 September, ransomware Unknown, forensic triage Yes. Notes point at WSO2-2026-5328, BOD 26-04, and NVD.
WSO2’s own advisory is the technical record:
- Overview: account takeover via authentication bypass.
- Description: “JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access.”
- Impact: unauthorized access, including administrative accounts and full account takeover. Scope changed (
S:C) on multi-tenant; 9.8 on single-tenant because impact stays inside one security-authority boundary. - Finder: Hacktron Team.
- Community users: apply the public fix in the advisory, or migrate to an unaffected version.
- Subscription holders: these update levels or higher.
| Product | Version | Update level |
|---|---|---|
| API Control Plane | 4.6.0 | 22 |
| API Control Plane | 4.5.0 | 58 |
| API Manager | 4.6.0 | 21 |
| API Manager | 4.5.0 | 57 |
| API Manager | 4.4.0 | 72 |
| API Manager | 4.3.0 | 108 |
| API Manager | 4.2.0 | 197 |
| API Manager | 4.1.0 | 257 |
| Traffic Manager | 4.6.0 | 21 |
| Traffic Manager | 4.5.0 | 56 |
| Universal Gateway | 4.6.0 | 21 |
| Universal Gateway | 4.5.0 | 57 |
NVD last-modified 25 September 04:17 UTC restates the same trains as CPE ranges (for example API Manager 4.1.0 before 4.1.0.257). NVD also lists WSO2 Carbon API Manager Rest API Utility CPEs that the vendor table does not name. Treat the vendor update-level table as the patch instruction; treat extra Carbon CPEs as ASSESSED in-scope via NVD, not as a second WSO2 advisory.
watchTowr is the public exploitation clock, published 16 September, now a week behind the catalog row:
- First honeypot hit 13 September 2026.
- Forged JWTs arrived with administrator privileges already in the token.
- Ganchev’s stated blast radius, to The Hacker News and SecurityWeek: the forged token yields access to every API backend endpoint and its credentials, plus consumer keys and secrets for every registered application. The gateway sits on the path to internal systems.
- One attacker, wrong product first; replay on API Manager succeeded. That is CONFIRMED as honeypot telemetry, not a census.
The Hacker News (25 September) and Cyber Daily (25 September) independently restated the KEV add against that 13 September watchTowr window. CISA’s alert does not cite watchTowr. Do not write CISA’s unpublished evidence as watchTowr’s.
The other new row in the same freeze is CVE-2026-71362, Adobe Commerce / Magento incorrect authorization, due the same day. It is sequenced below. It is not this Daily Top.
Why it matters
WSO2 API Manager is the box that decides who may call which API, and often the box that holds the consumer keys for those calls. A JWT the product should have rejected, accepted as an administrator, is not “an auth library bug.” It is the identity plane of the integration layer.
Two operational lies will show up in tickets this weekend:
- “CISA said path traversal, we grepped uploads.” The catalog title and short description are the wrong primitive. The CWE on the same JSON object is 347. If your KEV workflow keys off CISA’s
vulnerabilityNamestring, you will hunt a file-write that the vendor never described. Inventory JWT validation, admin sessions, and consumer-key access — then still apply the update level. - “We patched WSO2 in the spring.” April/May’s fix exists. watchTowr’s September tokens, and CISA’s 24 September row, are what you are answering. Update level on the running train is the close, not the date you last opened a WSO2 ticket.
CISA-ADP’s SSVC triple — active, automatable, total — is why the due date is three days. BOD 26-04’s forensic-triage flag means the ticket is not closed when the update-level integer ticks. A gateway that has been accepting forged admin JWTs since mid-September may already have issued or copied credentials. The patch does not rewind that.
No public victim count. CISA, WSO2, watchTowr, The Hacker News, SecurityWeek, and Cyber Daily do not name an actor, a ransomware affiliate, or a confirmed customer breach. Cyber Daily’s earlier 16 September piece noted WSO2’s own customer count (on the order of a thousand, across banking, government, telecom, and logistics, in 90-plus countries) as product exposure, not as a victim list. RWP is not treating named logos in secondary reporting as compromises.
Internet-facing API Manager is the practical condition. SSVC automatable yes is CISA-ADP’s statement, not a mass-scan census.
Who / what is affected
| Asset | What to assume | Status |
|---|---|---|
| WSO2 API Manager 4.1.0 through 4.6.0 below the tabled update level | In scope | CONFIRMED vendor |
| API Control Plane 4.5.0 / 4.6.0 below table | In scope | CONFIRMED vendor |
| Traffic Manager 4.5.0 / 4.6.0 below table | In scope | CONFIRMED vendor |
| Universal Gateway 4.5.0 / 4.6.0 below table | In scope | CONFIRMED vendor |
| Same trains at or above the listed update level | Vendor close for this CVE | CONFIRMED vendor |
| Carbon API Manager Rest API Utility (NVD CPE only) | Possibly in scope | ASSESSED via NVD; not in WSO2-2026-5328 product list |
| Multi-tenant vs single-tenant | Same bug; CVSS 10.0 vs 9.8 | CONFIRMED vendor |
| Named victims | None published | UNKNOWN |
| OT / ICS / process | Not claimed | No evidence |
| CISA ransomware field | Unknown | CONFIRMED catalog |
Internet-reachable publisher/devportal/gateway endpoints on those trains are the inventory unit. That is configuration, not a JWT recipe.
Technical context
RWP is not reproducing token headers, algorithm names beyond the vendor’s “unsupported algorithm,” or request bodies.
What the primary records give defenders:
- Primitive. Network-reachable JWT authentication. Token signed with an algorithm the product does not support. Product accepts it. Unauthenticated access, including admin. CWE-347.
- Prerequisite. An affected WSO2 component that performs that JWT check, reachable by the attacker. No user click. No valid victim password in the vendor description.
- Not claimed by the vendor. Path traversal, unrestricted file upload, or RCE as the 5430 primitive. Those words are CISA’s KEV short description. They are not WSO2-2026-5328.
- Follow-on that watchTowr assessed, not that CISA documented. Backend endpoint access, consumer key/secret exposure, request interception on the gateway path. Treat as ASSESSED from watchTowr’s 16 September statements, not as a CISA victim report.
ATT&CK mapping for what is stated:
- Exploit public-facing application (T1190) against the WSO2 JWT authentication surface.
- Valid accounts (T1078) via a forged token the product treats as legitimate.
- Use of application access tokens (T1550.001 class) is a follow-on risk of owning the API control plane; it is not observed tradecraft in CISA’s row.
Follow-on that is not claimed: a named APT, ransomware-Known, confirmed credential theft at a named customer, or OT/process impact.
Threat / exploitation status
| Claim | Status | Basis |
|---|---|---|
In KEV, added 24 Sep, due 27 Sep, catalog 2026.09.24 count 1723 | CONFIRMED | CISA alert + JSON |
| Exploitation in the wild | CONFIRMED as KEV criterion | CISA; CISA-ADP SSVC active |
| Forged admin JWTs on honeypots from 13 Sep | CONFIRMED as watchTowr telemetry | THN 16 Sep; SecurityWeek; Cyber Daily |
| JWT algorithm-mismatch, CWE-347, CVSS 10.0 / 9.8 | CONFIRMED | WSO2-2026-5328; CVE.org; NVD |
| KEV title “path traversal” / file upload / RCE | CONFIRMED as CISA text; not the vendor primitive | JSON row vs WSO2 advisory |
| Victim count / actor | UNKNOWN | No named set in CISA, WSO2, watchTowr |
| Ransomware use | Unknown | Catalog field |
| Forensic triage required | Yes | Catalog field |
| SSVC active / automatable / total | CONFIRMED as CISA-ADP, 24 Sep stamp | NVD |
| OT / physical-process impact | Not claimed | No evidence |
High confidence on: CVE ID, KEV dates, due date, catalog version and count, CVSS 10.0/9.8, CWE-347, product and update-level table, forensic-triage flag, ransomware Unknown, the CISA-title vs vendor-primitive mismatch, watchTowr’s 13 September honeypot date. Moderate confidence that internet-reachable API Manager is the dominant real-world condition (SSVC automatable + product role; no public census). Low confidence on CISA’s unpublished exploitation evidence, on any victim identity, on whether CISA’s path-traversal sentence describes a second bug, and on whether the update level displaces credentials already copied.
What defenders should do
- Inventory the four product names and the update-level integer, not “we have WSO2.” API Manager / Control Plane / Traffic Manager / Universal Gateway, train, update level, and whether the publisher, devportal, or gateway is reachable from untrusted networks. Record internet exposure for BOD 26-04. NVD’s extra Carbon utility CPE is a second pass, not a substitute for the vendor table.
- Preserve, then patch, then assume the token was already accepted. Snapshot gateway/auth logs, admin-account lists, application consumer keys and secrets, and routing changes before you reboot onto the new update level. Apply the tabled update level or the community fix in WSO2-2026-5328. Confirm the running build is at or above that integer. CISA’s notes do not say the patch removes a foothold already taken.
- Hunt JWT acceptance, not a webshell. Unexpected administrator sessions, new admin users, consumer-key access that does not match a change ticket, gateway routing edits in the 13–24 September window. Tokens whose signing algorithm is not in your configured set are a human-review trigger. Do not close “no PHP in
/tmp.” This is not [yesterday’s WordPress include](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/).
- Do not let the KEV title drive the scanner signature. If your KEV pipeline keys off “path traversal” or “unrestricted file upload,” add an exception that this row is CWE-347. Ticket the JWT configuration and the update level.
- Rotate what the gateway can mint. If the instance was internet-reachable and below the tabled update level after 13 September, rotate admin credentials, application consumer keys and secrets, and any backend credentials stored in the product. That is containment after a possible token accept, not a confirmation of breach.
- Sequence the rest of the federal list. Same catalog freeze: CVE-2026-71362 (Adobe Commerce / Magento APSB26-92, customer-session identity switch, CVSS 9.1, due 27 September; Adobe’s 18 August bulletin still says it is not aware of in-the-wild exploits; Sansec reported blocking attempts in August; The Hacker News cites Previdian one Australian IP on 10 September). Due today, already assessed: [F5 APM CVE-2026-94127](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/), [Check Point CVE-2026-85102](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/) and CVE-2026-93616, Arista VeloCloud CVE-2026-93952. [Zyxel CVE-2026-7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/) was due yesterday.
This is not an exploitation guide. Use WSO2’s update-level table.
RWP assessment
Score 8.8. Same-week KEV add, a three-day BOD 26-04 clock, unauthenticated administrative takeover on the API identity plane, and a catalog-title mismatch that will send scanners looking for the wrong artifact. That is the highest-leverage new row in catalog 2026.09.24.
It outranks CVE-2026-71362 (Adobe Commerce / Magento, same freeze, same due date, CVSS 9.1, customer-account identity switch) as a daily because WSO2’s primitive is administrative takeover of the API control plane, the vendor patch is months old with September honeypot traffic, and Magento’s August APSB26-92 was already in the StyleSmuggler sequence. Customer ATO is real. It is not “the gateway accepted an admin JWT.” It outranks a second day on [F5 94127](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/) because Friday’s due date is not a new technical finding. It outranks [WordPress CVE-2026-87902](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/) because that story shipped yesterday and is still not on KEV (2026.09.24 still has no 87902 row). It outranks JetBrains TeamCity CVE-2026-63077 ransomware-use coverage (BleepingComputer 24 September; KEV row still dated 5 August, ransomware Known) because that CVE has been catalogued since August; a secondary restatement is not a first KEV add. It outranks CCCS’s Roundcube CVE-2026-48842 exploitation notice and CISA/FBI’s 23 September ICS-integrator fact sheet (Weekly OT lane; no new CVE).
The failure mode to sand down is “KEV says path traversal” and its twin, “we patched WSO2 in May.” If the running update level is below the table and the gateway still validates JWTs, you are in CISA’s denominator. If you only grepped uploads, you inventoried the wrong bug.
What we are watching
- Whether CISA revises the KEV
vulnerabilityNameand short description to CWE-347, or documents a second primitive. - Whether ransomware-use flips off Unknown.
- Whether WSO2, watchTowr, or a national CERT names a victim class or an actor.
- Sunday’s close rate on 5430 and 71362, and Friday’s close rate on F5 94127, Check Point 85102/93616, and Arista 93952.
- Any attempt to treat a compromised API gateway in front of an industrial app as OT impact without process evidence.
Sources
- CISA — Adds two KEV (24 September 2026)
- CISA KEV JSON feed
- CISA Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- WSO2 — WSO2-2026-5328 / CVE-2026-5430
- CVE.org — CVE-2026-5430
- NVD — CVE-2026-5430
- The Hacker News — WSO2 and Adobe Commerce added to CISA KEV (25 September 2026)
- The Hacker News — WSO2 JWT bypass exploitation attempts (16 September 2026)
- SecurityWeek — Enterprises warned of WSO2 attacks (16 September 2026)
- Cyber Daily — WSO2 CVE-2026-5430 added to KEV (25 September 2026)
- Adobe — APSB26-92
- CVE.org — CVE-2026-71362
- NVD — CVE-2026-71362
- Sansec — APSB26-92 Magento account takeover (11 August 2026)
- CISA — Adds four KEV (22 September 2026)
- [RWP Daily Top, 24 September 2026 — WordPress CVE-2026-87902](/posts/2026-09-24-wordpress-cve-2026-87902-lfi-rce/)
- [RWP Daily Top, 23 September 2026 — F5 CVE-2026-94127](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/)
- [RWP Daily Top, 22 September 2026 — Zyxel CVE-2026-7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/)
- [RWP Daily Top, 16 September 2026 — vCenter CVE-2026-59310](/posts/2026-09-16-vmware-vcenter-cve-2026-59310-ransomware/)
Sources
- CISA — Adds two KEV including CVE-2026-5430
- CISA — KEV JSON feed catalog 2026.09.24
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- WSO2 — Security Advisory WSO2-2026-5328 / CVE-2026-5430
- CVE — CVE-2026-5430
- NVD — CVE-2026-5430
- The Hacker News — WSO2 and Adobe Commerce flaws added to CISA KEV
- The Hacker News — Active exploitation attempts target WSO2 JWT bypass
- SecurityWeek — Enterprises warned of attacks exploiting WSO2 vulnerability
- Cyber Daily — WSO2 API Manager vulnerability added to CISA KEV
- Adobe — APSB26-92 Adobe Commerce / Magento
- CVE — CVE-2026-71362
- NVD — CVE-2026-71362
- Sansec — Adobe patches critical Magento account takeover APSB26-92
- CISA — Adds four KEV 22 September 2026