Home / Aug 26, 2026 / Story
0
#1 The Hacker News general August 25, 2026 at 06:12 UTC

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

By [email protected] (The Hacker News)

AI Summary

CISA added CVE-2026-21962 (CVSS 10.0) to its Known Exploited Vulnerabilities catalog — a maximum-severity unauthenticated RCE flaw affecting Oracle HTTP Server and Oracle WebLogic Server exploitable via HTTP without credentials. Security teams running WebLogic should treat this as an emergency patch priority given the CVSS 10.0 score and confirmed active exploitation in the wild.

Relevance score: 88.0/100

# More from August 26