#2
The Hacker News
general
September 16, 2026 at 05:18 UTC
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
By [email protected] (The Hacker News)
AI Summary
CVE-2026-5430 (CVSS 9.8), a critical JWT authentication bypass in WSO2 API Manager that allows forged admin tokens via improper cryptographic signature verification, is under active exploitation in the wild, as confirmed by watchTowr. Attackers with forged admin tokens can gain full control of enterprise API management infrastructure, making immediate patching essential for any organization running WSO2 API Manager.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →