24h | 7d | 30d

Overview

  • Oracle Corporation
  • Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in

20 Jan 2026
Published
25 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
42.02%

Description

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Statistics

  • 10 Posts
  • 2 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

🚨 Kritischer Security Alert (CVSS 10.0)
CISA warnt vor Angriffen auf Oracle HTTP Server & WebLogic Proxy Plug-in (CVE-2026-21962).

Risiko: Path Traversal & Remote Code Execution ohne Authentifizierung (Vollständige Übernahme).
Status: Exploits/PoC öffentlich auf GitHub.
⚡Updates aus dem Oracle Critical Patch Update (Januar!!!) umgehend einspielen!

#ITSecurity #CyberSecurity #Oracle #WebLogic #CISA #SysAdmin #PatchManagement

heise.de/news/Attacken-auf-Ora

  • 1
  • 1
  • 0
  • 21h ago
Profile picture fallback

Geopolitical tensions escalate as the US launches "Operation Economic Outcast" against Iran, imposing new sanctions amidst Strait of Hormuz disputes (Aug 25). Canada is set to announce retaliatory tariffs against the US (Aug 25). The UK and Ukraine formalized an AI defense partnership (Aug 24).

In technology, Nvidia's AI chips remain a focal point, with Taiwan indicting nine individuals for illegal AI server exports to China (Aug 24). Hybrid bonding is advancing as a foundational technology for enhanced semiconductor performance (Aug 25).

Cybersecurity: CISA issued a warning regarding the active exploitation of an Oracle WebLogic vulnerability (CVE-2026-21962), urging immediate patching (Aug 25). ReliaQuest also confirmed an employee fell victim to a social engineering attack (Aug 25).

#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

📰 CISA Adds Actively Exploited Oracle Flaw to KEV Catalog

CISA adds actively exploited Oracle vulnerability CVE-2026-21962 to its KEV catalog. Flaw affects Oracle HTTP Server & WebLogic Server Proxy Plug-in. Federal agencies must patch. #CVE #Oracle #CISA #KEV #PatchNow

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

🚨 Critical Threat Intel: CVE-2026-21962 impacts Oracle HTTP Server & Weblogic Proxy Plug-in via access control bypass. Review exploitation patterns, web access detection queries, and active endpoint hardening actions.
thecybermind.co/jily

  • 0
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
CISA ordered immediate patching of CVE-2026-21962, a widely exploited unauthenticated remote code execution flaw in Oracle WebLogic components.
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
CISA ordered urgent patching of CVE-2026-21962, a critical unauthenticated RCE flaw in Oracle HTTP Server and WebLogic Server Proxy plugin, actively exploited since January. #OracleWebLogic #CISA #China
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
📢 Exploitation active de CVE-2026-21962 dans Oracle HTTP Server — ajout au catalogue KEV de la CISA GBHackers, publié le 25 août 2026. La CISA (U.S. Cybersecurity and Infrastructure Security Agency) a officiellement ajouté… 🟡 vérification factuelle moyenne #OracleHTTPServer #CISAKEV #Cyberveille
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
CVE-2026-21962 (CVSS 10.0, CISA KEV): unauth attackers gain complete data access via Oracle HTTP Server & WebLogic Proxy Plug-Ins. Apply Oracl’s January Patch. 3-day CISA deadline. Query: magnify.modat.io/search?query...
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
The CISA orders federal agencies to patch actively exploited Oracle flaw by August 27 The CISA has added a maximum-severity Oracle vulnerability, CVE-2026-21962, to its Known Exploited Vulnerabilities catalog after confirming active exploitation....
  • 0
  • 0
  • 1
  • 8h ago

Overview

  • Zimbra
  • Collaboration

13 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
1.51%

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Here's a concise overview of recent geopolitical, technology, and cybersecurity developments:

Geopolitical: The US has declared an "economic D-Day" against Iran, which is now threatening Strait of Hormuz disruption. China completed its largest South China Sea naval base at Antelope Reef.

Cybersecurity: Norway's public services were hit by a major DDoS attack on August 25. Iran-linked cyberattacks are increasingly targeting critical infrastructure in the UK and US. Over 270 Zimbra servers have been compromised via a high-severity RCE flaw (CVE-2026-73570).

Technology: Apple unveiled its M6 and M5 Ultra chips on August 25, significantly boosting AI performance in new Macs.

#AnonNews_irc #Cybersecurity #Anonymous #News

  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks 🔗 Read more: www.helpnetsecurity.com/2026/08/25/z... #exploit #vulnerability #cybersecurity @shadowserver.bsky.social
  • 0
  • 1
  • 0
  • 18h ago
Profile picture fallback
悪用が確認されたZimbraの脆弱性、米CISAが3日以内のパッチ適用を指示(CVE-2026-73570) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47359/
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Over 270 Zimbra Collaboration Suite servers were breached in active attacks exploiting CVE-2026-73570, an unauthenticated RCE flaw in the SNMP monitoring component. Synacor patched it in ZCS 10.1.20. #Zimbra #CVE-2026-73570 #Polska
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

11 Aug 2026
Published
25 Aug 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
2.93%

KEV

Description

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Statistics

  • 5 Posts
  • 10 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

If you've missed any super dope research from @lobsterjerusalem recently, pleez don't miss it anymore:

Oh no the internet is awash with AI slop PoCs, send poor Jonathan tiny cupcakes and quick: vulncheck.com/blog/death-by-20

SharePoint RCE:
vulncheck.com/blog/cve-2026-63

  • 3
  • 4
  • 0
  • 1h ago
Profile picture fallback

En las últimas 24 horas, una masiva filtración expone datos de 70,000 agentes marroquíes, mientras una vulnerabilidad crítica en Microsoft SharePoint pone en riesgo sistemas corporativos; simultáneamente, el botnet Kimwolf v7 avanza en ataques a dispositivos IoT y la emblemática lista Bugtraq reanuda actividades para fortalecer la defensa cibernética. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 25/08/26 📆 |====

🔓 JABAROOT ELEVÁ LA GUERRA DE LOS ESPÍAS: FILTRA DATOS DE 70,000 AGENTES MARROQUÍES

El grupo de hackers Jabaroot ha expuesto una base de datos que contiene las identidades de más de 70,000 miembros de los servicios de inteligencia y seguridad de Marruecos. Esta filtración representa un serio riesgo para la seguridad nacional y coloca en alerta a organismos de todo el mundo, dada la sensibilidad de la información comprometida. La publicación de los archivos continuará en las próximas horas, lo que podría ampliar aún más el impacto de esta brecha. Mantente informado sobre esta amenaza creciente. Descubre todos los detalles y el análisis de esta filtración aquí 👉 djar.co/ozZgH

🛡️ ANÁLISIS TÉCNICO DE LA VULNERABILIDAD REMOTA CVE-2026-63520 EN MICROSOFT SHAREPOINT

Se ha identificado una vulnerabilidad crítica de ejecución remota de código en Microsoft SharePoint, catalogada como CVE-2026-63520. Esta falla se debe a una instanciación no restringida de tipos .NET, lo que permite a atacantes ejecutar código malicioso a distancia si no se aplica un parche oportuno. Esta vulnerabilidad puede comprometer la integridad de sistemas corporativos y exponer datos sensibles. Se recomienda a los administradores revisar el análisis técnico y aplicar las actualizaciones de seguridad cuanto antes. Consulta el informe completo con recomendaciones de mitigación aquí 👉 djar.co/SzG0s

🤖 KIMWOLF V7: EVOLUCIÓN DEL BOTNET ORIENTADO A DISPOSITIVOS ANDROID IOT

La nueva versión del botnet Kimwolf, etiquetada como v7, ha mejorado sus capacidades para atacar dispositivos Android IoT mediante técnicas avanzadas de fingerprinting DDoS utilizando el protocolo HTTP/2. Además, incorpora resolución C2 con Ethereum ENS y enrutamiento de respaldo a través de la red Tor para aumentar su resiliencia. Esta evolución representa una amenaza mayor para la infraestructura IoT y los usuarios, evidenciando la creciente sofisticación de las ciberamenazas. Entiende cómo funciona y cómo proteger tus dispositivos. Profundiza en su análisis técnico aquí 👉 djar.co/dXQj4

📢 LA LISTA DE DIFUSIÓN ORIGINAL DE BUGTRAQ VUELVE A ESTAR ACTIVA

Bugtraq, la lista de difusión más emblemática para la divulgación responsable y discusión sobre vulnerabilidades y exploits, ha reactivado su servicio tras un tiempo de inactividad. Esta plataforma sigue siendo un recurso fundamental para profesionales de la seguridad informática, ofreciendo información detallada y análisis actualizados que permiten anticiparse a amenazas emergentes. Si buscas estar a la vanguardia en seguridad cibernética, no puedes perderte esta herramienta clave en el sector. Accede a la lista y su comunidad aquí 👉 djar.co/hS0rf

🤖 ¿EXISTE UN MEJOR MODELO DE IA PARA HACKING? | XBOW

Con la rápida evolución de los modelos de inteligencia artificial, el debate sobre cuál es el "mejor" para hacking se intensifica. Sin embargo, expertos señalan que más importante que elegir un modelo único es enfocarse en la orquestación y la integración con sistemas de seguridad robustos que amplifiquen su eficiencia. Este enfoque integral permite una defensa más adaptativa y precisa frente a las ciberamenazas dinámicas de hoy. Explora esta perspectiva innovadora para transformar tu estrategia de ciberseguridad. Lee el análisis completo aquí 👉 djar.co/VuoH

🎙️ ENTREVISTA EXCLUSIVA CON MARIANO M DEL RÍO, FUNDADOR DE SECURETECH

En esta entrevista, Mariano M del Río comparte su visión sobre las tendencias actuales en seguridad informática, los desafíos que enfrentan las organizaciones y cómo la innovación tecnológica está redefiniendo la protección digital. Su experiencia y liderazgo en SECURETECH aportan insights valiosos para profesionales que buscan fortalecer sus defensas y anticipar amenazas. No te pierdas esta conversación llena de estrategias y consejos prácticos para mantenerse seguro en el entorno digital actual. Accede a la entrevista completa aquí 👉 djar.co/iBym

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.

securityonline.info/sharepoint

  • 0
  • 0
  • 0
  • 14h ago

Bluesky

Profile picture fallback
🚨 CVE-2026-55040 + CVE-2026-63520 can be chained to bypass authentication and achieve RCE on Microsoft SharePoint Server. Censys sees 329,000 Internet-facing servers. Read the advisory: https://bit.ly/4qKJSUc #CVE202655040 #CVE202663520
  • 0
  • 2
  • 0
  • 8h ago
Profile picture fallback
Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain
  • 0
  • 1
  • 0
  • 21h ago

Overview

  • Red Hat
  • Red Hat build of Keycloak 26.4
  • rhbk/keycloak-operator-bundle

18 Aug 2026
Published
20 Aug 2026
Updated

CVSS
Pending
EPSS
2.79%

KEV

Description

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.

Statistics

  • 2 Posts
  • 14 Interactions

Last activity: 18 hours ago

Fediverse

Profile picture fallback

CVE-2026-18963: #Keycloak arbitrary account takeover via session confusion using simple HTTP requests. 😱

Nice find and (allegedly) not even AI-powered at its core.
A working exploit is publicly available. Given Keycloak's widespread use in critical auth systems, this appears to be flying a bit under the radar so far.

If you run Keycloak, it needs your attention *now*.

github.com/Red-Darkin/CVE-2026

  • 7
  • 4
  • 0
  • 18h ago
Profile picture fallback

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

thehackernews.com/2026/08/crit

> Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.

#keycloak

  • 2
  • 1
  • 0
  • 20h ago

Overview

  • WatchGuard
  • WatchGuard Agent

25 Aug 2026
Published
25 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
Pending

KEV

Description

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.

Statistics

  • 2 Posts
  • 12 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.

nvd.nist.gov/vuln/detail/CVE-2

  • 4
  • 8
  • 0
  • 14h ago
Profile picture fallback

Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.

securityonline.info/watchguard

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • WatchGuard
  • WatchGuard Agent

25 Aug 2026
Published
25 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

Statistics

  • 2 Posts
  • 4 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback
  • 0
  • 4
  • 0
  • 14h ago
Profile picture fallback

Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.

securityonline.info/watchguard

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
24 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
5.58%

Description

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Statistics

  • 3 Posts
  • 3 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.

securityonline.info/sharepoint

  • 0
  • 0
  • 0
  • 14h ago

Bluesky

Profile picture fallback
🚨 CVE-2026-55040 + CVE-2026-63520 can be chained to bypass authentication and achieve RCE on Microsoft SharePoint Server. Censys sees 329,000 Internet-facing servers. Read the advisory: https://bit.ly/4qKJSUc #CVE202655040 #CVE202663520
  • 0
  • 2
  • 0
  • 8h ago
Profile picture fallback
Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain
  • 0
  • 1
  • 0
  • 21h ago

Overview

  • Weidmueller Interface
  • IE-SR-2TX-WL

25 Aug 2026
Published
25 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.52%

KEV

Description

The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username containing shell metacharacters, an unauthenticated attacker with network access to the device can escape the command context and execute arbitrary commands with root privileges.

Statistics

  • 2 Posts

Last activity: 19 hours ago

Fediverse

Profile picture fallback

A critical Weidmueller router flaw, CVE-2026-63586 (CVSS 9.8), lets attackers execute arbitrary commands with root privileges. Patch devices immediately.

securityonline.info/weidmuelle

  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback

🔒 New CSAF advisory published

VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587

Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: weidmueller.csaf-tp.certvde.co

  • 0
  • 0
  • 0
  • 20h ago

Overview

  • OpenSSL
  • OpenSSL

25 Aug 2026
Published
25 Aug 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time. The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length. FIPS impact: no The FIPS module is not affected, as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.

securityonline.info/openssl-se

  • 0
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
OpenSSL 4.0.2 Released with Important Security and Bug Fixes Patches CVE-2026-18798, CVE-2026-63072, CVE-2026-63076, CVE-2026-14456, CVE-2026-14457, CVE-2026-54874, and CVE-2026-54876. #Linux
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
OpenSSLの脆弱性(CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #ssh #openssl #ssl security.sios.jp/vulnerabilit...
  • 0
  • 1
  • 0
  • 3h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 6 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Looks like this FreeBSD vuln is going to keep on giving for a while.

FreeBSD-SA-26:57.unix

[...]

III. Impact
An unprivileged local user can exploit this use-after-free to escalate privileges.

IV. Workaround
No workaround is available.

  • 1
  • 5
  • 0
  • 8h ago
Showing 1 to 10 of 64 CVEs