오라클 웹로직의 보안 취약점이 발견되어 불법 접근이 가능해졌다.
미국 사이버 보안 및 인프라 보안청(CISA)은 오라클 HTTP 서버와 웹로직 서버에 영향을 미치는 심각한 보안 취약점을 KEV 목록에 추가했다. 이 취약점(CVE-2026-21962)은 CVSS 점수가 10.0으로, HTTP를 통해 네트워크 접근이 가능한 공격자가 인증 없이 민감한 데이터에 접근할 수 있게 한다. 이러한 취약점은 현재 활발하게 악용되고 있는 것으로 판단된다.
A security flaw in Oracle WebLogic allows unauthenticated attackers to access critical data.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a serious security vulnerability affecting Oracle HTTP Server and WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, tracked as CVE-2026-21962, has a CVSS score of 10.0 and allows unauthenticated attackers with network access via HTTP to access sensitive data. Evidence suggests that this vulnerability is currently being actively exploited.