CuraSec

Act active

WSO2 API Manager JWT Bypass CVE-2026-5430 Under Active Exploitation

2026-09-16 15:25 UTC · The Hacker News · read the source ↗ #wso2#jwt-bypass#api-security
  • Engineer — Act: CVSS 9.8, public PoC on GitHub, and active exploitation of JWT signature bypass enabling forged admin tokens — patch WSO2 API Manager to the latest patched release immediately and audit API Manager admin audit logs for unauthorized token-based access.
  • SOC/IR — Act: Active exploitation via forged admin JWTs creates a detectable anomaly — hunt for unusual admin-level API calls or JWT tokens with unexpected issuer or signature fields in WSO2 API Manager logs since the PoC became public.
  • Leader — Plan: WSO2 API Manager is common enterprise middleware; confirm whether it is in your environment and verify engineering has this patched this sprint — not yet KEV-listed or board-level but a 9.8 with live exploitation warrants a status check.
  • Signals: CVE-2026-5430 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.