SECURITY·중요도 9·2026. 09. 16.·The Hacker News

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

── KO ──────────────────

WSO2 API Manager의 JWT 우회 취약점이 적극적으로 악용되고 있다는 보고.

WSO2 API Manager에서 발견된 심각한 보안 취약점(CVE-2026-5430)이 실제로 악용되고 있는 것으로 확인되었습니다. 이 취약점은 암호화 서명 검증이 부적절하여 계정 탈취로 이어질 수 있습니다. Hacktron 팀이 이 취약점을 발견하고 보고했습니다. CVSS 점수는 9.8/10.0으로 매우 높습니다.


── EN ──────────────────

A critical JWT bypass vulnerability in WSO2 API Manager is under active exploitation in the wild.

A critical security flaw (CVE-2026-5430) in WSO2 API Manager has been found to be actively exploited in the wild. The vulnerability involves improper verification of a cryptographic signature, potentially leading to account takeover. The Hacktron Team has been credited with discovering and reporting the flaw, which carries a high CVSS score of 9.8/10.0.

원문 보기 →목록으로