< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-25T11:42:35+05:30

Oracle WebLogic Server Vulnerability CVE-2026-21962 Exploited by Unauthenticated Attackers

A critical vulnerability (CVE-2026-21962) in Oracle WebLogic Server allows unauthenticated attackers to access sensitive data, with CISA confirming active exploitation. Federal agencies are urged to apply patches by August 27, 2026, to mitigate risks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

Read original article

*** END OF TRANSMISSION ***