Active exploitation attempts target WSO2 API Manager JWT bypass
A critical vulnerability CVE-2026-5430 (CVSS 9.8) in WSO2 API Manager allows bypassing JWT signature verification and forging admin tokens. According to watchTowr, the flaw is already actively exploited in real attacks and can lead to account takeover.
- Vulnerability CVE-2026-5430 rated CVSS 9.8 out of 10
- Issue is improper verification of JWT cryptographic signature
- Attacks already observed in the wild per watchTowr
- Exploitation allows forging admin tokens and account takeover
Read next
Security