Back to all news
Security

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

The Hacker News·September 16, 2026·1 min read
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

A critical WSO2 API Manager flaw, CVE-2026-5430 (CVSS 9.8), is under active exploitation, per watchTowr. The issue involves improper cryptographic signature verification, enabling account takeover. Hacktron Team discovered and reported the vulnerability. JWT authentication bypass allows forged admin tokens, posing severe risk to affected deployments.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store