Accueil > Accueil > Global Security Mag Online
http://www.globalsecuritymag.fr/
Articles
-
CISA orders federal agencies to patch actively exploited Oracle flaw by August 27– Expert Comments
25 août, par Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs — afficheCISA has added a maximum-severity Oracle vulnerability, CVE-2026-21962, to its Known Exploited Vulnerabilities catalog after confirming active exploitation.
The flaw carries a CVSS score of 10.0 and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS.
The vulnerability can be exploited remotely over HTTP without authentication or valid credentials, potentially allowing attackers to access, modify or delete critical data.Oracle originally disclosed and patched CVE-2026-21962 on January 20, 2026, as part of its January Critical Patch Update. In March, researchers reported exploitation attempts after exploit code became publicly available.
CISA has ordered federal agencies to address the vulnerability by August 27.
An expert with Suzu Labs offers perspective on the matter.Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“CVE-2026-21962 had a patch on January 20, and CloudSEK recorded exploitation attempts against its honeypot on January 22, followed by broader automated scanning. CISA added it to the KEV catalog on August 24, 216 days after the patch. Federal agencies now have three days to remediate something attackers have had seven months to exploit.
“In January, agencies could have applied the Critical Patch Update inside a normal maintenance window and moved on. Seven months of delay while exploitation attempts and automated scanning were already being observed from rented VPS infrastructure changed the math. BOD 26-04 requires forensic triage at this severity tier, so agencies now have to assess whether compromise occurred during that seven-month exposure period alongside applying the patch.
“BOD 26-04's 16-tier remediation matrix is well-designed for the problem it solves. For a vulnerability in the KEV, automatable, and yielding total control of a public-facing asset, the clock is three days with forensic triage. In this case, CISA's August 24 KEV addition produced an August 27 federal remediation deadline, while CISA's obligation is to update the catalog "as quickly as possible," with no numerical SLA. EPSS ranked this in the top 1.4%, Shodan shows roughly 79,000 exposed Oracle HTTP Server instances, and CISA's own SSVC record dates active exploitation to January 21 while classifying the vulnerability as automatable with total technical impact.
“Three days to remediate is the right call. Seven months to trigger it turned a maintenance window into a forensic investigation.”
-
Vigilance.fr - Tenable Nessus : SQL injection dated 25/06/2026
25 août, par Vigilance.frAn attacker can use a SQL injection of Tenable Nessus, dated 25/06/2026, in order to read or alter data.
View online : https://vigilance.fr/vulnerability/... -
Vigilance.fr - Tenable Nessus : injection SQL du 25/06/2026
25 août, par Vigilance.frUn attaquant peut provoquer une injection SQL de Tenable Nessus, du 25/06/2026, afin de lire ou modifier des données.
Voir en ligne : https://vigilance.fr/vulnerabilite/... -
Vigilance.fr - Asterisk Open Source : multiple vulnerabilities dated 25/06/2026
25 août, par Vigilance.frAn attacker can use several vulnerabilities of Asterisk Open Source, dated 25/06/2026.
View online : https://vigilance.fr/vulnerability/... -
Vigilance.fr - Asterisk Open Source : multiples vulnérabilités du 25/06/2026
25 août, par Vigilance.frUn attaquant peut employer plusieurs vulnérabilités de Asterisk Open Source, du 25/06/2026.
Voir en ligne : https://vigilance.fr/vulnerabilite/...
GS Days