● On the wire
Ubuntu OpenJDK 11 Important Denial of Service Vulnerabilities USN-8674-1//I pointed an agent at a bootloader. It found bugs but not useful ones//MISP v2.5.45 released - Overmind Everywhere, LDAP Reworked, Security Hardened and Many Fixes//Ubuntu 24.04 curl Important Info Exposure Vuln USN-8670-1 CVE-2026-8932//Ubuntu 26.04 AsyncHttpClient Important Information Exposure CVE-2026-55688//Ubuntu OpenJDK 25 Important User Authorization Issues USN-8681-1//Knowing what not to attack//ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)//Debian Emacs Critical Code Exec DoS Issue DSA-6468-1 CVE-2026-6861//Ubuntu 26.04 OpenJDK 17 Security Issues - USN-8676-1 - Multiple Threats//Debian webkit2gtk Important App Denial-of-Service Vulnern DSA-6463-1//ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)//Ubuntu OpenSSL Important Denial of Service Vulnern USN-8678-2//Cisco Advance Notification for Publication of September 2, 2026, Security Advisories//Ubuntu 24.04 libheif Critical Buffer Overflow Security Updates USN-8683-1//Ubuntu OpenJDK 11 Important Denial of Service Vulnerabilities USN-8674-1//I pointed an agent at a bootloader. It found bugs but not useful ones//MISP v2.5.45 released - Overmind Everywhere, LDAP Reworked, Security Hardened and Many Fixes//Ubuntu 24.04 curl Important Info Exposure Vuln USN-8670-1 CVE-2026-8932//Ubuntu 26.04 AsyncHttpClient Important Information Exposure CVE-2026-55688//Ubuntu OpenJDK 25 Important User Authorization Issues USN-8681-1//Knowing what not to attack//ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)//Debian Emacs Critical Code Exec DoS Issue DSA-6468-1 CVE-2026-6861//Ubuntu 26.04 OpenJDK 17 Security Issues - USN-8676-1 - Multiple Threats//Debian webkit2gtk Important App Denial-of-Service Vulnern DSA-6463-1//ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)//Ubuntu OpenSSL Important Denial of Service Vulnern USN-8678-2//Cisco Advance Notification for Publication of September 2, 2026, Security Advisories//Ubuntu 24.04 libheif Critical Buffer Overflow Security Updates USN-8683-1//
CISA inserisce Oracle HTTP Server/WebLogic Proxy Plug-in nel catalogo KEV per sfruttamento attivo
Top story — News

CISA adds Oracle HTTP Server/WebLogic Proxy Plug-in to KEV catalog for active exploitation

CISA has added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog after finding evidence of active exploitation against Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The flaw is a critical access control vulnerability that can be exploited remotely via HTTP without credentials. An attacker with network access can read, modify, or delete critical data and, in some scenarios, gain…

Read the article →
From the newsroom
Spotlight
More news