Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
ID: 53702b5c-8e1b-53f8-889b-c74d49cb3927
STIX ID: report--53702b5c-8e1b-53f8-889b-c74d49cb3927
Feed Name: The Hacker News
Threat Score
CISA added CVE-2026-21962 (CVSS 10.0) — an improper access control vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in that allows unauthenticated HTTP-based compromise — to its Known Exploited Vulnerabilities catalog after multiple reports (GreyNoise, CloudSEK) of active exploitation; patches were released in January but exploitation persisted, prompting a federal directive to apply fixes by August 27, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
