← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 24, 2026 · 18:50via Malware.news

Oracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 2

Brief

Serial number: AV26-042 Date: January 21, 2026 Updated: August 24, 2026

On January 20, 2026, Oracle published a security advisory to address vulnerabilities in multiple products.

Update 1

On January 21, 2026, a proof of concept (PoC) for the vulnerability CVE-2026-21962 became publicly available.

CVE-2026-21962 is a vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware which may allow a remote attacker to obtain unauthorized access.

Update 2

On August 24, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21962 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.

Read more on Malware.news