Threat Intelligence

Critical WSO2 API Manager Flaw Under Active Attack: Patch Now

The Hacker News · 16 Sept 2026
Key Takeaway If your business uses WSO2 API Manager, apply the available security patches immediately, as attackers are already exploiting this flaw to gain full administrative access.

A severe security flaw in WSO2 API Manager is being actively exploited by attackers, according to research firm watchTowr. The vulnerability, tracked as CVE-2026-5430 with a near-maximum severity score of 9.8, stems from a failure to properly verify cryptographic signatures on JWT authentication tokens. Tokens signed with unsupported algorithms are wrongly accepted as valid, allowing attackers to forge tokens with administrator privileges and take over accounts entirely.

The flaw affects WSO2 API Manager versions 4.1.0 through 4.6.0, as well as the API Control Plane, Traffic Manager, and Universal Gateway products. WSO2 released an advisory and fixes in May 2026, but watchTowr's honeypot network detected real-world exploitation attempts beginning in mid September 2026, with forged tokens carrying built-in administrator access. Researchers warn that successful exploitation could expose every API backend endpoint, along with credentials, consumer keys, and secrets for all registered applications, and could also let attackers intercept sensitive data flowing between internal systems.

Because API Manager sits between external requests and internal systems, a compromise here can act as a launchpad for broader network intrusion. WSO2 has published patches for both community users and support subscription holders.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.