WSO2 API Manager JWT bypass faces active exploitation attempts using forged tokens with administrator privileges.