HackerFeeds

CyberSecurity News

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

The Hacker News
· September 16, 2026

AI summary

A critical security flaw in WSO2 API Manager is being actively exploited, as discovered by watchTowr. The vulnerability allows for improper verification of a cryptographic signature, potentially leading to account takeover. It has a high CVSS score of 9.8 out of 10. The flaw was discovered and reported by Hacktron Team. The issue involves a JWT authentication bypass that can be exploited with forged admin tokens.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/active-exploitation-attempts-target.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.