CISA Adds Oracle HTTP Server Vulnerability to Known Exploited Catalog
CISA has added CVE-2026-21962, an Oracle HTTP Server and WebLogic Server Proxy Plug-in vulnerability, to its Known Exploited Vulnerabilities Catalog due to active exploitation.
Tag
2 results in the archive.
CISA has added CVE-2026-21962, an Oracle HTTP Server and WebLogic Server Proxy Plug-in vulnerability, to its Known Exploited Vulnerabilities Catalog due to active exploitation.
An Oracle database SQL injection vulnerability was exploited to compile and run the Khunt post-exploitation toolkit entirely within the database engine, avoiding writing executables to disk.