August 26, 2026
- Oracle’s 1,449-patch bundle did not protect against CVE-2026-21962. The actively exploited flaw is an unauthenticated, low-complexity HTTP issue caused by improper access control. CISA confirms exploitation, and The Register explains the patch gap. (discussion) · Vulnerabilities & Exploits