Back to all news
Security

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The Hacker News·August 25, 2026·1 min read
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

CISA added a maximum-severity Oracle WebLogic Server and HTTP Server flaw, CVE-2026-21962 with a CVSS score of 10.0, to its Known Exploited Vulnerabilities catalog on Monday, citing active exploitation. The vulnerability allows unauthenticated attackers with network access via HTTP to access critical data, posing a significant risk to affected systems.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store