logo

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

ID: 6f275d64-dde7-519d-9fca-be52808bbca1

STIX ID: report--6f275d64-dde7-519d-9fca-be52808bbca1

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Pierluigi Paganini

...
...

CISA added a critical unauthenticated RCE, CVE-2026-21962 (CVSS 10.0), impacting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in to its Known Exploited Vulnerabilities catalog; the flaw affects specified 12.2.1.4.0/14.x versions and can be exploited remotely without credentials to access or modify critical data. CloudSEK honeypot telemetry shows active exploitation of this CVE alongside older WebLogic RCEs, and CISA has mandated federal remediation by August 27, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.