UNDERCOVERED IN US

CISA adds seven exploited vulnerabilities to KEV catalog

On 2026-08-24, CISA added CVE-2026-21962 (Oracle HTTP Server and Weblogic Server Proxy Plug-in improper access control) to its Known Exploited Vulnerabilities catalog. On 2026-08-25 and 2026-08-26, CISA added six additional known exploited vulnerabilities including CVE-2026-60004 (Gitea code injection) and CVE-2015-3246 (Red Hat Libuser race condition).

12 reportsprimary · other

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

json:cisa-kevprimary36d ago kagi ↗

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data. Action: Apply mitigations per vendor instructions

🚨 [CISA-2026:0824] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0824 ) CISA has added one new vulnerability to its Known Ex

mastodon:infosec-exchangeother36d ago kagi ↗

🚨 [CISA-2026:0824] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0824 ) CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder

🤖 CVE-2026-21962 (CVSS 10.0): actively exploited flaw in Oracle WebLogic Server and Oracle HTTP Server, added to CISA KEV. Unauthenticated attackers can access critical data over HTTP. 🔗 https:// th

mastodon:infosec-exchangeother35d ago kagi ↗

🤖 CVE-2026-21962 (CVSS 10.0): actively exploited flaw in Oracle WebLogic Server and Oracle HTTP Server, added to CISA KEV. Unauthenticated attackers can access critical data over HTTP. 🔗 https:// thehackernews.com/2026/08/acti vely-exploited-oracle-weblogic-flaw.html # CVE # CyberSec # InfoSec

🏆 New Achievement! Ten Point Oh, Your Honor! This court finds Oracle WebLogic Server and Oracle HTTP Server guilty of harboring CVE-2026-21962 — a CVSS 10.0, maximum-severity flaw allowing unauthenti

mastodon:infosec-exchangeother35d ago kagi ↗

🏆 New Achievement! Ten Point Oh, Your Honor! This court finds Oracle WebLogic Server and Oracle HTTP Server guilty of harboring CVE-2026-21962 — a CVSS 10.0, maximum-severity flaw allowing unauthenticated attackers full network access via HTTP to seize instances and tamper with critical data. The defendant offered no authentication requirement whatsoever. CISA has entered the verdict into its Kno

CVE-2026-60004: Gitea Gitea — Gitea Code Injection Vulnerability

json:cisa-kevprimary35d ago kagi ↗

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account. Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL

CISA Adds One Known Exploited Vulnerability to Catalog

rss:cisa-advisoriesprimary35d ago kagi ↗

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-60004 Gitea Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based

Exploitation active de CVE-2026-21962 dans Oracle HTTP Server — ajout au catalogue KEV de la CISA

stream:bsky-jetstreamother35d ago kagi ↗

📢 Exploitation active de CVE-2026-21962 dans Oracle HTTP Server — ajout au catalogue KEV de la CISA GBHackers, publié le 25 août 2026. La CISA (U.S. Cybersecurity and Infrastructure Security Agency) a officiellement ajouté… 🟡 vérification factuelle moyenne #OracleHTTPServer #CISAKEV #Cyberveille GBHackers, publié le 25 août 2026. La CISA (U.S. Cybersecurity and Infrastructure Security Agency) a

🚨 [CISA-2026:0825] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0825 ) CISA has added one new vulnerability to its Known Ex

mastodon:infosec-exchangeother35d ago kagi ↗

🚨 [CISA-2026:0825] CISA Adds One Known Exploited Vulnerability to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0825 ) CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder

🚨 Critical Threat Intel: CVE-2026-21962 impacts Oracle HTTP Server & Weblogic Proxy Plug-in via access control bypass. Review exploitation patterns, web access detection queries, and active endpoint

mastodon:infosec-exchangeother34d ago kagi ↗

🚨 Critical Threat Intel: CVE-2026-21962 impacts Oracle HTTP Server & Weblogic Proxy Plug-in via access control bypass. Review exploitation patterns, web access detection queries, and active endpoint hardening actions. https:// thecybermind.co/jily

CISA Adds Six Known Exploited Vulnerabilities to Catalog

rss:cisa-advisoriesprimary34d ago kagi ↗

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability CVE-2021-23758 Ajax.NET Professional Deserializa

CISA warns that attackers are exploiting a critical Oracle HTTP Server and WebLogic proxy flaw that requires no login. Federal agencies must patch by August 27. Listen/Read: https:// hackread.com/cisa

mastodon:mstdn-socialother34d ago kagi ↗

CISA warns that attackers are exploiting a critical Oracle HTTP Server and WebLogic proxy flaw that requires no login. Federal agencies must patch by August 27. Listen/Read: https:// hackread.com/cisa-warns-agenci es-patch-oracle-weblogic-proxy-flow/ # CyberSecurity # CISA # Oracle # WebLogic # Vulnerability

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0826 ) CISA has added 6 new vulnerabilities to its Known Ex

mastodon:infosec-exchangeother34d ago kagi ↗

🚨 [CISA-2026:0826] CISA Adds 6 Known Exploited Vulnerabilities to Catalog ( https:// secdb.nttzen.cloud/security-ad visory/detail/CISA-2026:0826 ) CISA has added 6 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the feder