🛡 Pentesting Web: post #245 — TG.ME

🔴 CVE-2026-21962: Explotación activa en Oracle WebLogic

Impacto: Crítico (CVSS 10.0)

CISA ha añadido esta vulnerabilidad al catálogo de vulnerabilidades explotadas (KEV). Permite la ejecución remota de código (RCE) sin autenticación en Oracle HTTP Server y WebLogic Server Proxy plugin.

Tecnologías afectadas: Oracle HTTP Server, WebLogic Server Proxy Plugin.

CVE: CVE-2026-21962

Fuente original: https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html