Home / Sep 17, 2026 / Story
0
#2 The Hacker News general September 16, 2026 at 05:18 UTC

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

By [email protected] (The Hacker News)

AI Summary

CVE-2026-5430 (CVSS 9.8), a critical JWT authentication bypass in WSO2 API Manager that allows forged admin tokens via improper cryptographic signature verification, is under active exploitation in the wild, as confirmed by watchTowr. Attackers with forged admin tokens can gain full control of enterprise API management infrastructure, making immediate patching essential for any organization running WSO2 API Manager.

Relevance score: 87.0/100

# More from September 17