CISA Flags Actively Exploited Oracle WebLogic Flaw CVE-2026-21962
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server to…
Oracle HTTP Server is a web server component of Oracle Fusion Middleware, based on Apache, that provides HTTP and HTTPS services for…
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance…
Oracle Database was the target of an attack where attackers used SQL injection to load Java code into the database, achieving code…
Attackers breached an organization's Oracle database via a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit named…
khunt is a post-exploitation toolkit that runs inside Oracle databases by compiling Java source code into stored schema objects. It enables command…
Cybersecurity researchers have uncovered an active, multi-wave campaign that uses social engineering lures themed around Adobe and Zoom updates, business document reviews,…
An application server whose internal console was targeted by the attacker's scripts testing default credentials. No deployment was confirmed.
A critical Linux kernel vulnerability, tracked as CVE-2026-64600 and named RefluXFS, has been disclosed by Qualys. The flaw, present in Linux kernels…
Oracle E-Business Suite Improper Privilege Management Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security…