U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
2026-08-25T14:51:36Z•ee88200160687f01fb240bc4474ff69b23460974f5e6ba76b6379524ea2b1765
CVE-2026-21962AI securityCISA KEVOracle HTTP ServerOracle WebLogic Server Proxy Plug-inWeedHackactive exploitationcritical infrastructurecyber espionagedata theftindustrial control systemsinfostealermalvertisingmalwarepasskeysphishingransomwaresession hijackingunauthenticated vulnerability
What happened
Security Affairs reports active exploitation of CVE-2026-21962, a CVSS 10.0 unauthenticated vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, prompting CISA to add it to the KEV catalog. The feed also covers ongoing malware distribution through fake Minecraft and GTA VI sites, phishing that enrolls attacker-controlled passkeys, cyber risks to road speed cameras and critical infrastructure, and a claimed zero-click technique targeting Grok chat histories.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- ee88200160687f01fb240bc4474ff69b23460974f5e6ba76b6379524ea2b1765
- Enrichment time
- 2026-08-25T14:51:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.