Critical WSO2 JWT Flaw Under Active Exploitation
⚠️ WSO2 users face active exploitation of CVE-2026-5430, a critical JWT signature verification flaw that enables account takeover. Affected products include API Manager, API Control Plane, Traffic Manager, and Universal Gateway across several 4.x releases; fixes and update levels have been published. WatchTowr reports in-the-wild attempts capturing forged admin JWTs on September 13, 2026, and urges immediate patching to prevent unauthorized access and lateral movement.
