CVE Tools
Back to feed
Exploited in the wild Oracle HTTP Server rce WebLogic Server Proxy Plug-in Oracle info-disclosure

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The Hacker News·By The Hacker News··1 min read
CVE Tools coverage

CISA has listed CVE-2026-21962 in its Known Exploited Vulnerabilities catalog after confirming active attacks against Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. This maximum-severity flaw (CVSS 10.0) stems from improper access control, allowing unauthenticated attackers over HTTP to gain full control or modify critical data. Although Oracle released patches earlier this year, threat actors have intensified exploitation efforts, with federal agencies required to remediate by August 27, 2026.