SECURITYTHE HACKER NEWS
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities catalog due to active exploitation. The vulnerability, identified as CVE-2026-21962 with a CVSS score of 10.0, allows unauthenticated attackers with network access via HTTP to critical data.
Mentioned
Related Signal