Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
What happened
watchTowr detected active in-the-wild exploitation of CVE-2026-5430, a critical JWT signature verification flaw in WSO2 API Manager that allows attackers to bypass authentication using forged tokens. The vulnerability, which affects API Manager versions 4.1.0 through 4.6.0, enables unauthorized access to administrative accounts and API backend credentials. WSO2 has released patches for all affected products to remediate the improper cryptographic signature verification.
Why it ranks #1
watchTowr detected active in-the-wild exploitation of CVE-2026-5430, a JWT signature verification flaw in WSO2 API Manager versions 4.1.0 through 4.6.0 that allows attackers to bypass authentication using forged tokens to access administrative accounts and API backend credentials, for which WSO2 has released patches.
Who should care
Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams
What to do
Apply the fixes as soon as possible to mitigate exploitation and ensure optimal protection.
- Impact
- high
- Urgency
- immediate
- Confidence
- high
- Scope
- enterprise
- Status
- actively exploited