Find notable cyber news and cases, enriched with sources, timelines, and signals.

WSO2 security patch release for CVE-2026-5430

Security Patch Release
First reported
Last updated
Happening score
H score 56
1 unique sources, 1 articles

Summary

Hide ▲

WSO2 released fixes and update levels for CVE-2026-5430, a critical JWT signature-verification flaw in WSO2 API Manager and related product lines that can lead to account takeover. The patches cover both community users and support subscription holders across multiple affected branches. Administrators should deploy the updates quickly because exploitation attempts have already been observed in the wild.

Related Happenings

Adobe security patch release for CVE-2026-48362

Security Patch Release
H score43 First: 11.08.2026 19:50 Last: 11.08.2026 19:50 Sources 1

About this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...

Gitea security patch release for CVE-2026-59774

Security Patch Release
H score65 First: 05.08.2026 14:04 Last: 05.08.2026 14:04 Sources 1

About this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...

VBulletin 6.2.2 security patch release for template-engine flaw

Security Patch Release
H score32 First: 27.07.2026 17:40 Last: 27.07.2026 17:40 Sources 1

About this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...

RabbitMQ maintainers security patch release for CVE-2026-57219

Security Patch Release
H score29 First: 14.07.2026 16:48 Last: 14.07.2026 16:48 Sources 1

About this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...

SimpleHelp security update for CVE-2026-48558

Security Patch Release
H score65 First: 15.06.2026 23:06 Last: 15.06.2026 23:06 Sources 1

About this happening: SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...

Timeline

  1. 16.09.2026 08:18 1 articles · 2h ago

    watchTowr honeypots capture forged JWTs with administrator privileges

    Exploitation Observed

    watchTowr observed active in-the-wild exploitation attempts against WSO2 API Manager on September 13, 2026, and its honeypot network captured JWT tokens arriving with baked-in administrator privileges. The forged tokens were suspected of being used to reach API backend endpoints and recover credentials, consumer keys, and secrets for registered applications.

    Show sources
  2. 16.09.2026 08:18 2 articles · 2h ago

    WSO2 releases fixes and update levels for CVE-2026-5430

    Mitigation Patch Update

    WSO2 states that fixes are available for community users through github[.]com/wso2/carbon-apimgt/pull/13752 and github[.]com/wso2/product-apim/pull/14167, and that support subscription holders can install the listed update levels across WSO2 API Control Plane, WSO2 API Manager, WSO2 Traffic Manager, and WSO2 Universal Gateway branches affected by CVE-2026-5430. The flaw allows JWT authentication to be bypassed when a token is signed with an unsupported algorithm, creating a path to unauthorized access and potential administrative account takeover.

    Show sources