oxhak on Nostr: A critical Oracle server vulnerability is being exploited in the wild, prompting the ...
A critical Oracle server vulnerability is being exploited in the wild, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-21962 and rated 10.0, the flaw affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. It requires no authentication: an attacker with network access over HTTP can gain unauthorized access to affected instances or create, delete, or modify critical data.
Oracle released fixes in January, but reports from GreyNoise and CloudSEK indicate that attackers have continued targeting the vulnerability. CloudSEK also observed exploitation of several older WebLogic remote-code-execution flaws in its honeypot network, suggesting that threat actors are reusing a small set of effective weaknesses against exposed deployments. Federal civilian agencies have been advised under Binding Operational Directive 26-04 to apply the necessary updates by August 27, 2026.
https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.htmlPublished at
2026-08-25 07:06:19 UTCEvent JSON
{
"id": "cce74f5a8dba75a124ae7d7fc683660e5e938669a4180373aeeb2cd4b92b7d64",
"pubkey": "81b26cb98224311ea520a9042bf9c7cc78d2725d0a99f9797afd9a8a35970aaa",
"created_at": 1787641579,
"kind": 1,
"tags": [],
"content": "A critical Oracle server vulnerability is being exploited in the wild, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-21962 and rated 10.0, the flaw affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. It requires no authentication: an attacker with network access over HTTP can gain unauthorized access to affected instances or create, delete, or modify critical data.\n\nOracle released fixes in January, but reports from GreyNoise and CloudSEK indicate that attackers have continued targeting the vulnerability. CloudSEK also observed exploitation of several older WebLogic remote-code-execution flaws in its honeypot network, suggesting that threat actors are reusing a small set of effective weaknesses against exposed deployments. Federal civilian agencies have been advised under Binding Operational Directive 26-04 to apply the necessary updates by August 27, 2026.\n\nhttps://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html",
"sig": "3bd4179500efaa499452802307f93ef41ddb4eaf6567d7189fc30c04ada3cf027b19e7a591bfd7a64e535d12f376f1fcc5cc60e79d9e8094cb6cfc7c6202c637"
}