Dossier
CVE-2026-21962
Coverage of CVE-2026-21962 in the Nexus archive.
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities catalog due to active exploitation. The vulnerability, identified as CVE-2026-21962 with a CVSS score of 10.0, allows unauthenticated attackers with network access via HTTP to critical data.