logo

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

ID: 53702b5c-8e1b-53f8-889b-c74d49cb3927

STIX ID: report--53702b5c-8e1b-53f8-889b-c74d49cb3927

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: [email protected] (The Hacker News)

...
...

CISA added CVE-2026-21962 (CVSS 10.0) — an improper access control vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in that allows unauthenticated HTTP-based compromise — to its Known Exploited Vulnerabilities catalog after multiple reports (GreyNoise, CloudSEK) of active exploitation; patches were released in January but exploitation persisted, prompting a federal directive to apply fixes by August 27, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.