Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

2026-08-25T07:24:00Z2e15c659503ff156849334b76c483ffbe3ce9441172db2ab646e0c3ac3f808e5
CVE-2026-18963CVE-2026-19478CVE-2026-21962CVE-2026-73570account-takeoveractive-exploitationandroid-malwareauthentication-bypassbackdoorciscoclickfixcritical-infrastructure-ics-plc-attackedr-bypassgitlabkeycloaklinux-rootkitmalwarenetscalernpmoraclercerustseo-poisoningstealersupply-chain-attackunauthenticated-accessweblogiczero-dayzimbra

What happened

The feed highlights widespread active cyber threats, including actively exploited critical vulnerabilities in Oracle WebLogic/HTTP Server, GitLab, and Zimbra; severe flaws in Keycloak, NetScaler, Cisco, and isolated-vm; malware and supply-chain campaigns targeting npm, Rust crates, Android vehicle systems, gamers, and Windows users; and espionage activity against governments and strategic sectors. Multiple reports describe unauthenticated remote code execution, account takeover, authentication bypass, defense evasion, and exploitation of internet-facing systems.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
2e15c659503ff156849334b76c483ffbe3ce9441172db2ab646e0c3ac3f808e5
Enrichment time
2026-08-25T07:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.