CISA Adds Oracle HTTP Server and Weblogic Server Vulnerability (CVE-2026-21962) to Known Exploited Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, CVE-2026-21962, to its Known Exploited Vulnerabilities (KEV) Catalog. This improper access control vulnerability in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in is actively being exploited, posing significant risks for unauthorized data access, creation, deletion, or modification.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai