// Alert

Oracle Health threat report

CVE-2026-21962, a maximum-severity improper access control flaw in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (CVSS 10.0), has been added to CISA's Known Exploited Vulnerabilities catalog following confirmed active exploitation. The vulnerability allows unauthenticated attackers with network access via HTTP to unauthorizedly access, modify, or delete critical data. Patches were released in January 2026, and exploitation attempts have been documented by GreyNoise and CloudSEK.

// Get alerts for Oracle Health