The record
Written from the 1 report below. Nothing here is unsourced.
- Attackers are actively exploiting a critical authentication bypass vulnerability in WSO2 API Manager, tracked as CVE-2026-5430 with a CVSS score of 9.8.
- The flaw lets JWT tokens signed with unsupported algorithms be accepted, allowing unauthorized access, compromise of administrative accounts, and full account takeover.
- Affected products include WSO2 API Manager, API Control Plane, Traffic Manager, and Universal Gateway across versions 4.1.0 to 4.6.0.
- WatchTowr's honeypot network captured forged JWT tokens with administrator privileges arriving on September 13, 2026, and the tokens are suspected of being used to access API credentials, consumer keys, and secrets of every registered application.
- WSO2 has released fixes through community pull requests and update levels for support subscription holders, and users are advised to apply the fixes as soon as possible.
What to watch next
- Whether more organizations confirm compromises or data theft involving stolen API credentials and secrets
- Further advisories or indicators of compromise from WSO2 or security researchers on attacker infrastructure
- Uptake of the released patches by affected organizations running WSO2 products
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
WSO2
1 quote · 1 outlet
“JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access”
In the article
…as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. " JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access ," according to an advisory released by WSO2 in May 2026. "Successful exploitation of the vulnerability may lead to unauthorized access, including potential compromise of administrative accounts and full account…
Yordan Ganchev
principal threat intelligence specialist at watchTowr
1 quote · 1 outlet
“The flaw exists in the service due to how JWT authentication accepts tokens signed with algorithms it does not support, then approves them anyway”
In the article
…to watchTowr, the vulnerability is now witnessing active in-the-wild exploitation attempts, with its honeypot network capturing JWT tokens arriving on September 13, 2026, with baked-in administrator privileges. " The flaw exists in the service due to how JWT authentication accepts tokens signed with algorithms it does not support, then approves them anyway ," Yordan Ganchev, principal threat intelligence specialist at watchTowr, said in a statement shared with The Hacker News. "So, it's easy to see why this is a critical bug (CVSS 10.0). It affects API Manager 4.1.0…
Coverage1
All filed from India
Named India · Wso2 · Hacktron Team · watchTowr · Yordan Ganchev
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
