Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
1. Executive summary A critical authentication bypass in WSO2 API Manager and related WSO2 gateway products — CVE-2026-5430, CVSS 10.0 (CRITICAL), CWE-347 (Improper
16 Sep 2026 · 8 min read
read →