Oracle WebLogic CVSS 10.0 Added to KEV — Active Exploitation Confirmed
CISA has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog as of August 24, confirming active exploitation in the wild. The flaw, rated CVSS 10.0, is an improper access control vulnerability affecting both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. Successful exploitation allows unauthenticated attackers to create, delete, or modify critical data and gain complete access to all accessible data on affected systems. Weaponised scripts and automated scanning are already being observed targeting internet-facing instances. FCEB agencies must remediate by August 27 under BOD 26-04. Oracle HTTP Server and the WebLogic proxy plug-in sit at the boundary between external users and internal applications, making this a high-priority perimeter risk. Any unpatched, network-reachable Oracle middleware instance should be treated as presumed compromised until verified otherwise.
CISA/NSA/FBI Joint Advisory: AI-Powered Attacks Targeting Siemens S7 PLCs
A joint advisory from CISA, NSA, and FBI warns that threat actors are using AI-generated exploit scripts to target internet-exposed Siemens S7 Series programmable logic controllers. The affected sectors include water and wastewater, energy, critical manufacturing, chemical, and food and agriculture. The AI-assisted approach lowers the skill barrier for OT exploitation, enabling actors who would previously lack the expertise to craft ICS-specific payloads to now generate functional attack code. Any organisation running Siemens S7 PLCs exposed to the internet or on bridged OT/IT networks should immediately audit exposure, enforce network segmentation, and apply detection rules from the advisory. This is the clearest confirmation yet that AI is being weaponised directly against industrial control systems, not just IT infrastructure.
SPIP CMS RCE (CVE-2026-77806) — Added to KEV, Exploited in the Wild
CISA added CVE-2026-77806 (CVSS 9.8) to the KEV catalog on August 24, confirming active exploitation. The vulnerability allows unauthenticated remote code execution in SPIP versions before 4.4.21. A public exploit is circulating. Any internet-facing SPIP instance should be upgraded to 4.4.21 immediately. SPIP is widely used in French-speaking government and institutional websites, making this a particular concern for European public-sector organisations.
China-Nexus APT Campaign: VMware vCenter Exploitation Spans 47 Countries
German incident response firm QUIRSO has published detailed analysis of the China-nexus APT campaign exploiting CVE-2026-59310 (VMware vCenter, CVSS 9.8). The actor, assessed as Chinese-speaking with UTC+08:00 operational hours, began exploiting the flaw five calendar days after public disclosure. The campaign has compromised 361 unique victim IPs across 47 countries, with Germany (55), the US (41), Turkey (38), Iran (26), and France (25) most affected. The attack chain includes JSP webshell deployment disguised as VMware performance monitoring tools, credential theft from vmdir, creation of persistent admin accounts, and lateral movement to ESXi hosts for Babuk-derived ransomware deployment. The use of reverse SSH binaries, WebSocket-based C2 with XOR-obfuscated addresses, and sudoers persistence through the perfcharts service account indicates a sophisticated, well-resourced operator. Patch to vCenter 9.1.0.0300+ or 8.0 U3k+ immediately and audit for indicators of compromise.
So What / Action
This is an unusually concentrated burst of critical exploitation. Four CVSS 9.8+ vulnerabilities hit the KEV in eight days, a nation-state actor is running ransomware operations from vCenter compromises across European infrastructure, and AI is being directly weaponised against industrial control systems. The patch window from disclosure to exploitation has collapsed to days, not weeks. Prioritise: (1) Oracle WebLogic/HTTP Server instances — CVSS 10.0, perimeter-facing, actively scanned; (2) Windows IPsec/VPN hosts running IKE — wormable, pre-auth RCE; (3) VMware vCenter — check for IOCs from the China-nexus campaign, especially cron jobs in /etc/cron.d/ referencing syslog or perf, unexpected admin accounts, and reverse SSH binaries; (4) Siemens S7 PLCs — audit all OT exposure, enforce air-gap discipline; (5) SPIP installations — upgrade immediately. If you run Oracle middleware at the edge, assume compromise and investigate, don't just patch.

