Skip to main content
CyberConfirmedHighDevelopingFeatured
7.8

Active exploitation of critical Oracle WebLogic vulnerability CVE-2026-21962

Threat actors are actively exploiting a CVSS 10.0 vulnerability in Oracle WebLogic Server Proxy Plug-in, allowing unauthenticated remote code execution or data manipulation. The flaw enables unauthorized access via HTTP requests, posing a severe risk to enterprise infrastructure relying on these components.

The Hacker Newsabout 16 hours agoUSengCredibility 59%View source

Score Breakdown

Mosaic Score7.8
Confidence0.9
Significance0.8
Source credibility0.6

Intelligence Tags

Entities

country
Source

Related signals

8 found