Oracle WebLogic Maximum-Severity Flaw Under Active Exploitation (CVE-2026-21962)
CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog on August 24, 2026. The vulnerability carries a CVSS score of 10.0 — the maximum — and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. It allows an unauthenticated attacker with HTTP network access to gain complete control of accessible data: creation, deletion, and modification of critical data, plus full access to all Oracle HTTP Server and WebLogic Proxy Plug-in reachable data. No credentials, no user interaction, no existing privileges required.
Oracle patched this in January 2026. That has not stopped exploitation. CloudSEK, GreyNoise, and SOCRadar have all confirmed active attacks. A CloudSEK honeypot captured exploitation within days of disclosure, alongside attacks chaining older WebLogic RCE flaws (CVE-2020-14882, CVE-2020-2551, CVE-2017-10271) — threat actors are treating WebLogic as a persistent attack surface, combining new and vintage vulnerabilities rather than moving on. The same CVE is also among those exploited by a China-linked threat actor delivering the SNOWLIGHT downloader across more than 100 countries. FCEB agencies have until August 27 to patch under BOD 26-04.
VMware vCenter Exploited by Suspected China APT Across 47 Countries (CVE-2026-59310)
CVE-2026-59310 is a CVSS 9.8 path traversal vulnerability in Broadcom VMware vCenter Server, added to KEV on August 18. A threat actor with network access to vCenter can execute arbitrary code without valid credentials. Broadcom disclosed it on July 29; exploitation began five days later, on August 3.
A suspected China-nexus APT has exploited this flaw to deploy backdoors and reverse_ssh binaries for persistent access. In at least one case, the campaign led to Babuk-derived ransomware deployment. 361 unique victim IP addresses have been identified across 47 countries, with Germany (55), the US (41), Turkey (38), Iran (26), and France (25) seeing the highest concentration. European infrastructure is heavily represented in the victim set. Microsoft IKE (CVE-2026-33824), SharePoint (CVE-2026-55040), and Apple macOS Screen Sharing (CVE-2026-65400) were all added to KEV the same day, all under active exploitation.
So What / Action
Two maximum-critical unauthenticated RCE vectors are under active exploitation right now, and neither requires sophisticated social engineering — just network access to an exposed service. The WebLogic flaw (CVSS 10.0) is as bad as it gets: unauthenticated, remote, complete data access. The vCenter flaw (CVSS 9.8) is being weaponised by a nation-state actor with ransomware follow-through and has already hit 47 countries, with European organisations disproportionately affected.
If you run Oracle HTTP Server or WebLogic Proxy Plug-in and have not applied the January 2026 Critical Patch Update, treat this as a P1 incident: patch immediately, then audit HTTP access logs for the exploitation IOCs published by CloudSEK and GreyNoise. For VMware vCenter, if patching is not yet complete, restrict network access to vCenter interfaces to management VLANs only and monitor for reverse_ssh and Babuk indicators. Both KEV entries carry BOD 26-04 compliance deadlines that have already passed for FCEB agencies; private-sector organisations should treat those deadlines as a floor, not a ceiling.

