Critical
CVE-2026-21962
Active Exploitation of CVE-2026-21962 Targeting Oracle HTTP and WebLogic Servers
Vendor / product: Oracle HTTP Server and Oracle WebLogic Server
Event date: 2026-08-24
Public PoC: Yes
First tracked by RiskWire: 2026-08-27
Named threat actors
China-linked threat actors
Sources & citations (1)
- Oracle's Summer of Contradictions: A $27 Billion Contract, Fresh Layoffs, and a Security Clock Ticki ad-hoc-news.de · 2026-08-28
References
See CVE-2026-21962 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →