# WSO2 API Manager JWT bypass sees active exploitation attempts

_Published Wednesday, September 16, 2026 at 10:07 AM EDT · Security · Latest · Tier 1 — Major_

![WSO2 API Manager JWT bypass sees active exploitation attempts — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjenXPNzZ8-fnZOSWlAtRwfZVCV0iy-vnK86gK4vmTGsWSjSS7x9a3k80NLsiEZUym2AjBaYj7pLtxyQju7Hiyl6ttQPyXEPMy7Gwn_bQTTTaUOB-8HbhJfYxl54Z3WE5yqKEoW1vvkCBukKwea-6DlpBiO6i08Zo0GhBoqgRsGGXadsOYy8COPUPQ7rn2w/s1700-nu-rw-lo-l85-e365/jwt-api.jpg)

A critical JWT-signature verification flaw in WSO2 API Manager and related products is seeing active exploitation attempts, according to watchTowr. The flaw, CVE-2026-5430, can allow tokens signed with unsupported algorithms to bypass authentication and potentially take over administrative accounts. WatchTowr said its honeypots captured tokens with embedded administrator privileges on September 13. WSO2 has released fixes for affected products and support-subscription update levels.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/active-exploitation-attempts-target.html)

---
Canonical: https://techandbusiness.org/newswire/wZMKSYXxhyR8EJw2u-v1nh
Published: 2026-09-16T14:07:52.573Z
Story chronology: 2026-09-16T05:18:06.000Z
Retrieved: 2026-09-16T16:22:44.054Z
Publisher: Tech & Business (techandbusiness.org)
