TODAY
Perfect-10 Oracle/Apache flaw hits KEV; 113 ransomware victims this week.
THE THREE
- KEV#1 · CVE-2026-21962
Apache
What: If you run Oracle WebLogic or Apache HTTP Server with the WebLogic Proxy Plug-in (versions 12.2.1.4.0 or 14.1.1), this CVSS 10.0 flaw — added to CISA's KEV list just yesterday — lets attackers fully compromise your web infrastructure with no authentication. Exploitation is already confirmed in the wild.
Why it moved: Actively exploited · KEV-listed this week · Everyone runs this · Critical severity · New this week
Who is exploiting: Actively-exploited (CISA KEV)
Action · Immediately isolate or patch Oracle WebLogic Proxy Plug-in on all affected servers.
- KEV#2 · CVE-2026-33824
Windows
What: This Windows IKE Extension flaw lets an unauthenticated attacker run arbitrary code over the network — meaning any Windows system using IPsec/IKE is potentially exposed to full takeover without any user interaction. With a 73% exploit probability and KEV-listed this week, active attacks are underway.
Why it moved: Actively exploited · Everyone runs this · Critical severity · 73% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Microsoft's patch for CVE-2026-33824 on all Windows systems immediately.
- KEV#3 · CVE-2026-8037
Progress
What: Progress LoadMaster — a widely used load balancer — has a command injection flaw that unauthenticated attackers are exploiting with near-certain success (99.6% EPSS), letting them run any command on the appliance and pivot into your network. This is a perimeter device, so compromise means attackers are inside.
Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply the Progress LoadMaster patch or take the appliance offline until patched.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 11M
- Relationships
- 67M
- Threat actors
- 289
- Indicators
- 575k
- Feeds live
- 0
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.