Critical 10.0
CVE-2026-5430
Exploitation of WSO2 API Manager Authentication Bypass (CVE-2026-5430)
Vendor / product: WSO2 API Manager
Event date: 2026-09-13
Public PoC: Yes
First tracked by RiskWire: 2026-09-30
Sources & citations (2)
- PraisonAI's Open-Source Agent Framework Shipped With Auth Disabled — Attackers Probed It in Under 4 Hours tech.yahoo.com · 2026-09-30
- El bug del ‘admin' que pagó US$5.000 a un chaval de 16 ecosistemastartup.com · 2026-10-03
References
See CVE-2026-5430 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →