VYPR
AI Brief2026-08-26· generated Aug 26, 2026

Active Exploitation Drives Urgent Patching for Oracle, Microsoft, Adobe

Oracle WebLogic, Microsoft Entra ID, and Adobe ColdFusion vulnerabilities are actively exploited, prompting urgent patching.

CISA has added Oracle WebLogic Server's CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation. This critical vulnerability, with a CVSS score of 10.0, allows unauthenticated attackers to remotely execute code. Oracle's Fusion Middleware is affected, specifically the WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. The urgency is underscored by CISA's mandate for federal agencies to patch within three days, indicating a high-priority threat. As reported by The Register Security, this flaw is easily exploitable and poses a significant risk to organizations running vulnerable Oracle products.

Microsoft has addressed a critical deserialization vulnerability (CVE-2026-69836) in Microsoft Entra ID, which has a CVSS score of 10.0 and is being actively exploited. This flaw allows unauthenticated attackers to execute code remotely over a network. The vulnerability is part of a larger batch of 25 disclosed by Microsoft, including other critical issues in Azure Arc (CVE-2026-69555, CVE-2026-65816) and Azure SQL Database (CVE-2026-69502). As detailed by The Hacker News, the active exploitation of the Entra ID flaw highlights the immediate need for patching.

Adobe is urging customers to immediately patch critical vulnerabilities in ColdFusion and Adobe Campaign Classic. CVE-2026-48282, a critical path traversal flaw in ColdFusion versions 2025.9, 2023.20 and earlier, could lead to arbitrary code execution. Additionally, CVE-2026-71398, a critical authorization vulnerability in Adobe Campaign Classic, also allows for arbitrary code execution. Both vulnerabilities have a CVSS score of 10.0, as noted by SecurityWeek.

Several critical vulnerabilities have been identified in Apache Tomcat, with CVE-2020-1938 and CVE-2016-8735 being particularly noteworthy. CVE-2020-1938, related to the Apache JServ Protocol (AJP), allows attackers to exploit trust assumptions in Tomcat configurations to potentially access sensitive files or execute code. CVE-2016-8735, on the other hand, enables remote code execution if JmxRemoteLifecycleListener is used and JMX ports are accessible. These flaws, affecting various versions of Tomcat, underscore the importance of secure configurations and timely patching, as discussed in relation to Operation Escaneo by Dark Reading.

Multiple critical vulnerabilities have been disclosed affecting Joomla extensions from miniorange.com. CVE-2026-77998 presents an unauthenticated authentication bypass in their SAML SSO plugins, while CVE-2026-77995 allows for arbitrary account takeover via cookie manipulation in the OAuth Client plugin. These flaws, affecting versions prior to 11.0.2 and 3.2.0 respectively, pose a significant risk to Joomla sites relying on these authentication mechanisms.

Oracle has released patches for a range of critical vulnerabilities, including CVE-2019-2725 in Oracle WebLogic Server, a critical RCE flaw affecting older supported versions. Additionally, CVE-2026-61241 addresses a critical vulnerability in the OID LDAP Server component of Oracle Fusion Middleware. These updates are part of Oracle's regular Critical Patch Update advisories, emphasizing the ongoing need for vigilance in maintaining Oracle product security.

Synthesized by Vypr AI
Active Exploitation Drives Urgent Patching for Oracle, Microsoft, Adobe · VYPR