<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — WSO2</title><description>Security vulnerabilities in WSO2&apos;s enterprise identity and API management platforms, including WSO2 Identity Server, API Manager, and related integration products deployed across financial services and enterprise environments. Combined article + CVE feed for the WSO2 beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>WSO2 CVSS 10 JWT Bypass Exploited in the Wild</title><link>https://0daynews.com/articles/2026-09-17-wso2-cve-2026-5430-cvss10-jwt-bypass-exploited/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-09-17-wso2-cve-2026-5430-cvss10-jwt-bypass-exploited/</guid><description>CVE-2026-5430 lets unauthenticated attackers forge JWTs and gain administrative access to WSO2 deployments. Active exploitation confirmed. Patch immediately.</description><pubDate>Thu, 17 Sep 2026 15:00:00 GMT</pubDate><category>WSO2</category><category>article</category></item><item><title>CVE-2022-29464 — WSO2 Multiple Products Unrestrictive Upload of File Vulnerability</title><link>https://0daynews.com/cve/cve-2022-29464/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-29464/</guid><description>Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.</description><pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate><category>WSO2</category><category>critical</category><category>cve</category></item></channel></rss>