VYPR
AI Brief2026-08-26· generated Aug 25, 2026

What you need to know today.

CISA adds exploited Oracle WebLogic flaw to KEV; Microsoft, Adobe patch critical RCEs.

CISA has added Oracle WebLogic Server's CVE-2026-21962 to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation. This critical vulnerability, with a CVSS score of 10.0, allows unauthenticated attackers to remotely execute code. The flaw affects Oracle Fusion Middleware's WebLogic Server component, specifically versions 10.3.6.0.0 and 12.1.3.0.0. Oracle has released patches, and CISA mandates federal agencies to apply them within three days. The vulnerability's ease of exploitation and high impact make it a prime target for threat actors. As The Register reported, this is a significant development requiring immediate attention.

Microsoft has addressed a critical vulnerability (CVE-2026-69836) in Microsoft Entra ID, rated with a CVSS score of 10.0, which allows for remote code execution. This flaw, along with several other critical vulnerabilities in Azure services, was patched in Microsoft's latest security update. The Entra ID vulnerability, in particular, has seen exploitation in the wild, as noted by Cyber Security News. Other Microsoft vulnerabilities patched include SSRF in Azure SQL Database (CVE-2026-69502), incorrect authorization in Azure Arc (CVE-2026-69555), and argument injection in Azure Managed Instance for Apache Cassandra (CVE-2026-65770).

Adobe has released patches for critical vulnerabilities in ColdFusion and Adobe Campaign Classic. CVE-2026-48282, a critical path traversal vulnerability in ColdFusion versions 2025.9, 2023.20 and earlier, could lead to arbitrary code execution. Additionally, Adobe Campaign Classic (ACC) is affected by an incorrect authorization vulnerability (CVE-2026-71398) that also permits arbitrary code execution. The Hacker News highlighted these critical flaws, emphasizing the need for immediate patching due to their high severity and potential for exploitation.

Several vulnerabilities affecting Apache Tomcat have been detailed, including CVE-2020-1938, a critical flaw related to the Apache JServ Protocol (AJP) that allows attackers to bypass security controls if Tomcat is configured to trust AJP connections. Another critical vulnerability, CVE-2016-8735, allows remote code execution if JmxRemoteLifecycleListener is used and JMX ports are accessible. Additionally, CVE-2017-12617, a high-severity flaw, permits arbitrary file writes when HTTP PUTs are enabled. While these have been known for some time, their continued relevance and potential for exploitation underscore the importance of keeping Tomcat updated.

Joomla extensions from miniorange.com are impacted by critical vulnerabilities. CVE-2026-77998 allows for unauthenticated authentication bypass via SAMLResponse parameter in miniOrange SAML SSO and related plugins. Furthermore, CVE-2026-77995 enables arbitrary account takeover in miniOrange OAuth Client by manipulating cookie values. These flaws pose a significant risk to Joomla sites using these extensions, potentially leading to complete account compromise.

Oracle has also released patches for other critical vulnerabilities, including CVE-2026-61241 in Oracle Internet Directory, which allows unauthenticated attackers to exploit an OID LDAP Server vulnerability. Another critical flaw, CVE-2026-70880, affects Oracle Hyperion Data Relationship Management, specifically its access and security components, enabling unauthenticated attackers to gain unauthorized access. These updates are part of Oracle's ongoing efforts to secure its extensive product suite.

Synthesized by Vypr AI
Oracle, Microsoft, Adobe Flaws Exploited · VYPR