Security
CISA flags exploited Oracle server flaw
Image: Primary CISA added CVE-2026-21962, a maximum-severity flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog, citing active exploitation. The reported improper-access-control issue can allow an unauthenticated attacker with HTTP network access to obtain unauthorized access or create, delete or modify critical data. Oracle released patches in January, and federal civilian agencies have been recommended to apply fixes by August 27 under Binding Operational Directive 26-04.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire

