Act
active
WSO2 API Manager JWT Bypass CVE-2026-5430 Under Active Exploitation
- Engineer — Act: CVSS 9.8, public PoC on GitHub, and active exploitation of JWT signature bypass enabling forged admin tokens — patch WSO2 API Manager to the latest patched release immediately and audit API Manager admin audit logs for unauthorized token-based access.
- SOC/IR — Act: Active exploitation via forged admin JWTs creates a detectable anomaly — hunt for unusual admin-level API calls or JWT tokens with unexpected issuer or signature fields in WSO2 API Manager logs since the PoC became public.
- Leader — Plan: WSO2 API Manager is common enterprise middleware; confirm whether it is in your environment and verify engineering has this patched this sprint — not yet KEV-listed or board-level but a 9.8 with live exploitation warrants a status check.
- Signals: CVE-2026-5430 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.