Enterprises Warned of Attacks Exploiting WSO2 Vulnerability
A critical WSO2 vulnerability patched earlier this year is now being exploited in the wild by threat actors seeking access to sensitive enterprise data.
WSO2 is an open source middleware platform that enables organizations to design, secure, integrate, and manage APIs, services, and identities across hybrid and multi-cloud environments.
The platform has nearly 1,000 enterprise customers worldwide in sectors such as banking, government, telecom, and logistics. Thousands more have adopted it through open source deployments, OEMs, and partners.
Exposure management firm WatchTowr warned on Tuesday that a vulnerability tracked as CVE-2026-5430, which WSO2 patched in April, is being exploited in malicious attacks.
The flaw carries a maximum CVSS score of 10. According to a vendor advisory issued in May, it can let attackers bypass authentication and take over accounts.
“JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access,” WSO2 explained, adding, “Successful...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE