CISA Warns of Critical Oracle HTTP Server Flaw (CVE-2026-21962) Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Oracle HTTP Server vulnerability, tracked as CVE-2026-21962, to its Known Exploited Vulnerabilities (KEV) Catalog due to confirmed active exploitation. This flaw, an improper access control issue affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, allows unauthenticated attackers to access and modify critical data without valid credentials. The vulnerability was added to the KEV Catalog on August 24, 2026, requiring federal agencies to prioritize its remediation.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai