#1
The Hacker News
general
August 25, 2026 at 06:12 UTC
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
By [email protected] (The Hacker News)
AI Summary
CISA added CVE-2026-21962 (CVSS 10.0) to its Known Exploited Vulnerabilities catalog — a maximum-severity unauthenticated RCE flaw affecting Oracle HTTP Server and Oracle WebLogic Server exploitable via HTTP without credentials. Security teams running WebLogic should treat this as an emergency patch priority given the CVSS 10.0 score and confirmed active exploitation in the wild.
Relevance score: 88.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →