Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Read full story on The Hacker News
Share
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
AI disclosure

Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.