Cybersecurity Hacking News

Active Exploitation of Critical WSO2 API Manager Authentication Bypass

Active Exploitation of Critical WSO2 API Manager Authentication Bypass

Attackers are reportedly forging administrator JWTs to bypass WSO2 API Manager authentication and reach backend endpoints, credentials, secrets, traffic, and internal services. Affected organizations should patch immediately, rotate credentials and tokens, and investigate API activity and persistence.

Sources (2)
Updated Sep 17, 2026
Active Exploitation of Critical WSO2 API Manager Authentication Bypass - Cybersecurity Hacking News | NBot | nbot.ai