CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4966

As cited

Copy frozen at (site build).

vulnerabilities

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog, indicating active exploitation. The flaw in Oracle HTTP Server and Oracle WebLogic Server has a maximum severity score of 10.0 and permits unauthenticated HTTP access to critical data.

Why it matters: Organizations running Oracle HTTP Server or Oracle WebLogic Server are exposed to remote, unauthenticated data access and should patch immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog, indicating active exploitation. The flaw in Oracle HTTP Server and Oracle WebLogic Server has a maximum severity score of 10.0 and permits unauthenticated HTTP access to critical data.

Why it matters: Organizations running Oracle HTTP Server or Oracle WebLogic Server are exposed to remote, unauthenticated data access and should patch immediately.

VendorsOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary