discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabil…

By Ravie Lakshmanan·Aug 25·thehackernews.com·2 min read

Intelligence analysis by Llama

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
Image: thehackernews.com

CISA has added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962, allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.

Why it matters

This story matters to someone following Security because it highlights a critical vulnerability in Oracle HTTP Server and Oracle WebLogic Server that is being actively exploited, and it emphasizes the importance of patching and securing these systems to prevent unauthorized access and data modification.

Imagine you have a super important computer system that lots of people need to access. But, if someone finds a secret way to get into the system without needing a password, they can do bad things like change important information or steal secrets. That's what's happening with Oracle WebLogic, a system that lots of companies use. Someone found a way to get into it without a password, and now lots of people are trying to fix it.

Analysis

Oracle WebLogic Flaw Overview

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962, allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.

Impact of the Flaw

Successful exploitation of the flaw can lead to unauthorized access to the instances or modification of critical data. Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data.

Active Exploitation

While patches for the flaw were released by Oracle earlier this January, it has since witnessed active exploitation efforts, per multiple reports from GreyNoise and CloudSEK. In February 2026, it emerged that a lone IP address ('193.24.123[.]42') was attempting to exploit multiple known vulnerabilities impacting Oracle WebLogic, Ivanti Endpoint Manager Mobile, GNU InetUtils, and GLPI. A month later, CloudSEK reported seeing exploitation efforts aimed at its honeypot network.

Recommendations

Pursuant to Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies have been recommended to apply necessary fixes by August 27, 2026, to safeguard their networks.

Key points

  • CISA has added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
  • The vulnerability, tracked as CVE-2026-21962, allows an unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
  • Successful exploitation of the flaw can lead to unauthorized access to the instances or modification of critical data.
  • Patches for the flaw were released by Oracle earlier this January, but it has since witnessed active exploitation efforts.
  • Federal Civilian Executive Branch (FCEB) agencies have been recommended to apply necessary fixes by August 27, 2026, to safeguard their networks.
The Upside

If this development plays out positively, it's possible that Oracle will release a patch that fixes the vulnerability quickly, and companies will be able to secure their systems before any more damage is done. Additionally, the fact that CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog may help raise awareness and prompt companies to take action to protect themselves.

The Downside

On the other hand, if this development plays out negatively, it's possible that the vulnerability will continue to be exploited, and companies will not be able to secure their systems in time. This could lead to significant data breaches and other security incidents, which could have serious consequences for companies and individuals.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsapplication-securityenterprise-securitynetwork-securityserver-securityvulnerabilityweb-security

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Aug 25, 2026

Source

thehackernews.com

Share

Topics

application-securityenterprise-securitynetwork-securityserver-securityvulnerabilityweb-security

Related

More from this desk

Aug 24·bleepingcomputer.com

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to create port-forwarding rules, exposing local network devices to the public internet. The flaw affects devices running EXOS/6.6.47 firmware and has no fix yet.

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.