
🚨 Hackers are actively exploiting a new critical (CVSS 10.0) unauthenticated RCE in Oracle WebLogic Server — CVE-2026-21962 — along with several older high-severity flaws (CVE-2020-14882/83, CVE-2020-2551, CVE-2017-10271). Exploitation of the new flaw began the same day public PoC dropped. Honeypots saw immediate automated attacks. Full details: https://gbhackers.com/hackers-exploit-critical-weblogic-rce-vulnerabilities/
Post summary
Hackers are actively exploiting CVE-2026-21962, a critical unauthenticated RCE in Oracle WebLogic, with a public PoC released the same day and automated attacks detected by honeypots.
