Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Cybersecurity · August 25, 2026

Cybersecurity·thehackernews.com

CISA has added a maximum-severity flaw in Oracle HTTP Server and WebLogic Server, tracked as CVE-2026-21962 with a perfect 10.0 CVSS score, to its Known Exploited Vulnerabilities catalog after confirming active attacks. The bug lets an attacker with only network access send a crafted request to read sensitive server data without any credentials. Organizations running affected Oracle deployments should treat patching as an urgent priority.

// source: thehackernews.com ↗

Back to Blog