The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition confirms that attackers are actively exploiting the vulnerability in real-world attacks. Organizations with affected Oracle infrastructure should identify exposed systems […]
Read the original article: