Security researchers at watchTowr confirmed this week that a critical flaw in WSO2 API Manager, tracked as CVE-2026-5430 with a near-maximum severity score of 9.8, is being actively exploited in the wild. Honeypot traffic first captured forged tokens on 13 September, and the exploitation attempts have continued since. The flaw lets an attacker bypass authentication entirely by presenting a JWT (a standard type of access token) signed with an algorithm the system shouldn’t accept, effectively forging a token with baked-in administrator privileges. Once inside, an attacker can reach every API backend, credential, and secret the platform manages.
Most UK SME owners have never heard of WSO2 and never will need to, it’s enterprise-grade middleware for managing APIs at scale. But that’s exactly why this story matters more broadly than the specific product name suggests. Almost every UK business now runs on a web of connected systems: your accounting software talks to your CRM, your website talks to your payment processor, your booking system talks to your calendar. All of that connective tissue runs on APIs, and API security has become one of the least visible, least understood risks in modern business technology, precisely because it happens silently between systems rather than in front of a person clicking a link.
The real lesson isn’t about WSO2, it’s about what you don’t know you’re running
If you’ve ever commissioned a custom app, an integration, or an internal tool from a developer or agency, there’s a reasonable chance it talks to other systems via an API, and a reasonable chance you couldn’t name which platform manages that authentication if asked. That’s not a criticism, it’s a normal position for a business owner to be in. But it means the responsibility for knowing whether a flaw like this affects you sits with whoever built or maintains your systems, and it’s worth confirming that someone is actually watching vulnerability disclosures on your behalf rather than assuming “someone” is.
This is precisely the kind of gap that shows up when a business has commissioned bespoke software over the years from different suppliers, with nobody holding the full picture of what’s connected to what. If that sounds familiar, a proper technical audit, of the kind CoolCoding carries out for UK businesses, is worth commissioning before a flaw like this becomes a live incident rather than a hypothetical one.
What to actually do this week
You don’t need to become an API security expert overnight. Three concrete steps: first, ask whoever manages your website, CRM, or any custom-built software whether they use WSO2 API Manager, or any API gateway product, and whether it’s patched. Second, if you’re planning a new app or integration build, ask your developer directly how token-based authentication is being handled and whether algorithm confusion attacks like this one are accounted for, a good technical partner should be able to answer that without hesitation. Third, if you’ve had bespoke systems built for you over several years by different suppliers, get an inventory done. You can’t secure what you don’t know exists.
The takeaway
A critical, actively exploited flaw in enterprise API software is a reminder that modern business risk increasingly lives in the invisible connections between your systems, not just in email inboxes or company laptops. If your business relies on any custom-built software or integrations, and most growing UK SMEs now do, this is the week to ask who’s actually watching for flaws like this on your behalf, and to get an honest answer before you need one.