Blog / tag

CVE-2026-21962, a CVSS 10.0 flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, went from a quiet January patch line item to a confirmed, actively exploited threat when CISA added it to the Known Exploited Vulnerabilities catalog on August 24, 2026. Patch now.