Critical Vulnerability in Oracle HTTP Server and WebLogic Server Proxy Plug-In Actively Exploited
The Cyber Security Agency of Singapore (CSA) has reported active exploitation of CVE-2026-21962, a critical vulnerability (CVSS score 10.0) affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-In. This flaw allows unauthenticated attackers to gain unauthorized access to critical data, including the ability to create, delete, or modify information. Oracle has released security updates to address the issue.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.