
CISA Warns Oracle HTTP Server Flaw Lets Unauthenticated Attackers Access and Modify Critical Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Oracle HTTP Server vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation. Tracked as CVE-2026-21962, the flaw affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA described it as an improper access control issue that […]
The post CISA Warns Oracle HTTP Server Flaw Lets Unauthenticated Attackers Access and Modify Critical Data appeared first on Cyber Security News.