Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
News Source : Internet
News Summary
- The u.s. Cybersecurity and Infrastructure Security Agency (CISA) added a maximum-severity security flaw to its Known Exploited Vulnerabilities (KEV) catalog.
- The vulnerability, tracked as CVE-2026-21962, allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
- Successful exploitation of the flaw can lead to unauthorized access to the instances or modification of critical data.
The U.S.
Never miss a story from us, subscribe to our newsletter