Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Linux 0.11 rewritten in idiomatic Rust, boots in QEMU

Linux 0.11 rewritten in idiomatic Rust, boots in QEMU Source: Hacker News

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six

Sogen – High-performance Windows and Linux userspace emulator

Sogen – High-performance Windows and Linux userspace emulator Source: Hacker News